adobe-commerce

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from npm rather than a raw installer, so this is not overtly malicious. However, all authentication and Adobe Commerce API traffic are routed through Membrane's third-party control plane/proxy instead of directly to Adobe, and the skill uses mutable `@latest` installs. That makes the trust and data-flow footprint moderately risky but still plausible for the stated integration purpose.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fadobe-commerce%2F@2d6d5096aadb43ef5e2a7edae806262b24ae6d66