WooCommerce Automation

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The business functions are broadly aligned with a WooCommerce automation skill, but install trust and backend identity are not fully coherent: the ecosystem uses transitive skill installation and same-org unpinned installers, and this skill names an `ecommerce-mcp` server that was not verified against the publisher while the repo documents a different MCP server. No strong evidence of credential theft or overt exfiltration appears in the skill text, so this is better classified as medium security risk rather than confirmed malware.

Confidence: 81%Severity: 59%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills-hub%2Fwoocommerce-automation%2F@74d83c9c53635b7f966083ceacb32cf06f2646e1
Security Audit — socket — WooCommerce Automation