woocommerce

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities match WooCommerce administration, but its data flow is mediated entirely through Maton-controlled proxy and connection services instead of official direct WooCommerce endpoints. That makes the skill internally coherent as a managed gateway integration, yet it concentrates credentials and sensitive commerce data in a third-party intermediary and enables high-impact business actions, creating medium-high security risk without clear evidence of outright malware.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fwoocommerce%2F@0674aa6cfed6edf374fe4ad9a41b7366f6487f8d