commercevault-edd-ecommerce-orchestrator
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions require the user to clone a repository from a personal GitHub account (
dhapat3927/mcp-edd-analytics-vantage) and execute installation commands (npm install,pip install -r requirements.txt). This code originates from an unverified source. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process e-commerce data from the Easy Digital Downloads REST API, which may include attacker-controlled content such as product descriptions or customer metadata.
- Ingestion points: Data retrieved through
vault.products.list,vault.orders.list, and customer segmentation endpoints inSKILL.md. - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the provided examples to protect the agent from data-driven instructions.
- Capability inventory: The skill possesses significant capabilities including product creation, order management, and license generation.
- Sanitization: There is no evidence of sanitization or schema validation applied to the external API data before it is processed by the agent.
Audit Metadata