commercevault-edd-commerce-orchestrator
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install a package named
mcp-edd-analytics-vantagevia npm and pip. It also directs users to clone a repository fromhttps://github.com/dhapat3927/mcp-edd-analytics-vantage.git. These sources are not associated with a known trusted organization or well-known service. - [COMMAND_EXECUTION]: The skill provides various CLI commands (e.g.,
commercevault serve,commercevault sync,commercevault export-analytics) that execute shell operations on the local machine and interact with external services, including database synchronization. - [CREDENTIALS_UNSAFE]: The skill requires the configuration of sensitive Easy Digital Downloads credentials (
EDD_CONSUMER_KEY,EDD_CONSUMER_SECRET) via environment variables or a.envfile. While secret management via environment variables is a standard practice, providing these keys to software from an untrusted source poses a risk of credential exposure. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting untrusted data from an external WordPress EDD installation.
- Ingestion points: Functions like
vault.products.list,vault.orders.list, andvault.customers.listinSKILL.mdfetch external data from the EDD REST API. - Boundary markers: There are no documented boundary markers or instructions to the agent to ignore embedded commands within the commerce data.
- Capability inventory: The skill has the capability to perform database writes (
commercevault sync), file exports (commercevault export-analytics), and license generation, which could be abused if malicious instructions are processed from the API data. - Sanitization: There is no evidence of sanitization or filtering of the external API content before it is processed by the agent.
Audit Metadata