commercevault-edd-commerce-orchestrator

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The business purpose is plausible and the requested EDD credentials are broadly proportionate, but the trust chain is weak: the skill is published by ara.so while execution comes from an unrelated GitHub repo, installed from mutable source with npm dependencies and no clear same-org release verification. The docs also appear inconsistent with official EDD authentication/API patterns, which further weakens confidence in data-flow integrity. No confirmed malware or hidden exfiltration is shown, but the third-party code will receive live store credentials, making this a high supply-chain risk skill.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:33 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fcommercevault-edd-commerce-orchestrator%2F@e74eb880dd30bb147a6b5d3b3df2426cfed0ae73ea6573f98d8ae12af1c79c78
Security Audit — socket — commercevault-edd-commerce-orchestrator