commercevault-edd-digital-commerce
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external packages and references source code hosted on a personal GitHub repository rather than a verified organization or the stated vendor's infrastructure.
- Evidence:
npm install @commercevault/edd-client(Unverified NPM scope) - Evidence:
pip install commercevault-edd(Unverified PyPI package) - Evidence:
https://github.com/dhapat3927/mcp-edd-analytics-vantage(Personal repository hosting core functionality) - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted commerce data (product titles, customer information, order metadata) and possesses the capability to perform high-impact actions, creating an attack surface for indirect instructions embedded in store data.
- Ingestion points: Data retrieved from WordPress stores via
client.products.list(),client.orders.list(), andclient.customers.get(), as well as payloads received throughclient.webhooks.register(). - Boundary markers: The documentation describes HMAC payload verification for data integrity, which mitigates tampering but does not isolate natural language instructions within the data fields.
- Capability inventory: The skill has the authority to create orders (
client.orders.create), issue refunds (client.orders.refund), generate license keys (client.licenses.generate), and export customer data to external cloud storage (client.customers.exportSegment). - Sanitization: There are no explicit instructions or middleware examples provided for sanitizing or filtering natural language content from external data sources before it is processed by the agent.
Audit Metadata