avada-commerce
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@membranehq/clipackage via npm. This is the official command-line interface provided by the skill's author (Membrane) and is a necessary component for the skill's functionality.\n- [COMMAND_EXECUTION]: The skill utilizesmembranecommands to authenticate users, search for connectors, and run actions. These executions are limited to the vendor's own verified toolset.\n- [DATA_EXFILTRATION]: No sensitive data exposure detected. The skill follows security best practices by delegating credential management to the Membrane server-side proxy, which prevents API keys or tokens from being processed or stored within the agent's local environment.\n- [PROMPT_INJECTION]: While the skill ingests third-party data from the AVADA Commerce API (creating an indirect prompt injection surface), the risk is minimal as the skill is designed for administrative e-commerce tasks and relies on standard agentic guardrails for data processing.
Audit Metadata