Sps Commerce

v1.0.0

SPS Commerce integration. Manage data, records, and automate workflows. Use when the user wants to interact with SPS Commerce data.

0· 44·0 current·0 all-time
byVlad Ursul@gora050
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description match the instructions: the skill directs the agent to use Membrane to manage SPS Commerce data. Requiring a Membrane account and network access is expected for this integration; no unrelated services, credentials, or system access are requested.
Instruction Scope
SKILL.md only instructs installing and using the Membrane CLI, creating/listing connections, discovering and running actions, and proxying requests through Membrane. It does not instruct reading unrelated files, accessing unexpected environment variables, or exfiltrating data to unknown endpoints. Note: proxying arbitrary paths through Membrane means Membrane will see requests/responses — this is within the skill's purpose but important for user privacy considerations.
Install Mechanism
No automated install spec is present (instruction-only). The doc asks the user to npm install -g @membranehq/cli — a public npm package. This is proportionate, but users should verify the package/repo authenticity before installing global CLI tools.
Credentials
The skill declares no required env vars or credentials and explicitly advises against asking the user for API keys, relying instead on Membrane to manage auth. This is appropriate and minimal for the described functionality. Users must still trust Membrane with SPS Commerce credentials because Membrane handles auth server-side.
Persistence & Privilege
The skill is not set to always: true, requests no persistent system changes, and provides only CLI-based runtime instructions. It does not modify other skills or system-wide settings.
Assessment
This skill is coherent: it uses Membrane as a proxy/connector to access SPS Commerce and asks you to install the Membrane CLI. Before installing or using it, verify the @membranehq/cli package and the Membrane service (homepage and GitHub repo) are legitimate and up to date; review Membrane's security/privacy docs because Membrane will see and manage SPS Commerce credentials and proxied data; avoid pasting any SPS Commerce API keys into chat or other places — use the browser-based connection flow the skill describes; and consider confirming the exact scopes/permissions granted during the Membrane connection flow and audit access logs for sensitive data access.

Like a lobster shell, security has layers — review code before you run it.

latestvk9789hrhpps7jjmwcdjrzpvfts84c5wn

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments