commercevault-edd-ecommerce-orchestrator

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions require the user to clone a repository from a personal GitHub account (dhapat3927/mcp-edd-analytics-vantage) and execute installation commands (npm install, pip install -r requirements.txt). This code originates from an unverified source.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process e-commerce data from the Easy Digital Downloads REST API, which may include attacker-controlled content such as product descriptions or customer metadata.
  • Ingestion points: Data retrieved through vault.products.list, vault.orders.list, and customer segmentation endpoints in SKILL.md.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the provided examples to protect the agent from data-driven instructions.
  • Capability inventory: The skill possesses significant capabilities including product creation, order management, and license generation.
  • Sanitization: There is no evidence of sanitization or schema validation applied to the external API data before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — commercevault-edd-ecommerce-orchestrator