avada-commerce

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @membranehq/cli package via npm. This is the official command-line interface provided by the skill's author (Membrane) and is a necessary component for the skill's functionality.\n- [COMMAND_EXECUTION]: The skill utilizes membrane commands to authenticate users, search for connectors, and run actions. These executions are limited to the vendor's own verified toolset.\n- [DATA_EXFILTRATION]: No sensitive data exposure detected. The skill follows security best practices by delegating credential management to the Membrane server-side proxy, which prevents API keys or tokens from being processed or stored within the agent's local environment.\n- [PROMPT_INJECTION]: While the skill ingests third-party data from the AVADA Commerce API (creating an indirect prompt injection surface), the risk is minimal as the skill is designed for administrative e-commerce tasks and relies on standard agentic guardrails for data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 08:56 AM