commercevault-edd-commerce-orchestrator
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The business purpose is plausible and the requested EDD credentials are broadly proportionate, but the trust chain is weak: the skill is published by ara.so while execution comes from an unrelated GitHub repo, installed from mutable source with npm dependencies and no clear same-org release verification. The docs also appear inconsistent with official EDD authentication/API patterns, which further weakens confidence in data-flow integrity. No confirmed malware or hidden exfiltration is shown, but the third-party code will receive live store credentials, making this a high supply-chain risk skill.
Confidence: 90%Severity: 81%
Audit Metadata