sap-commerce-cloud

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/query-items.sh

No clear malicious behavior is present. The script is an administrative HAC query client, but it carries meaningful operational security risk because it submits generated Groovy to a privileged scripting console, only weakly validates the query, may mishandle special input during Groovy embedding, stores credentials temporarily, and offers an insecure TLS mode. Use only with trusted URLs, authorized HAC credentials, and strict server-side permissions; robustly parse and enforce read-only queries and avoid embedding untrusted text in source code.

Confidence: 94%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:20 AM
Package URL
pkg:socket/skills-sh/emenowicz%2Fsap-commerce-skill%2Fsap-commerce-cloud%2F@697ee5b0e141f58ca27f738555e2d3916334933fba854de90a7ee0f968319d32
Security Audit — socket — sap-commerce-cloud