Woocommerce

Security checks across malware telemetry and agentic risk

Overview

This WooCommerce skill appears legitimate, but it gives an agent broad ability to change or delete live store data without clear safety checks.

Install only if you trust Membrane and intend to let an agent operate on WooCommerce data. Use a least-privileged WooCommerce account, test against a staging store when possible, and require explicit confirmation with exact IDs before any create, update, delete, or non-GET proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly documents destructive operations such as deleting orders, products, customers, and coupons without any instruction to require user confirmation, authorization checks, or safeguards before execution. In an agent setting, this increases the risk of accidental or unauthorized destructive actions against a live store, especially when the skill is meant to be used operationally.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The proxy request feature allows arbitrary live API requests to WooCommerce while emphasizing convenience, but it does not warn that requests may modify production data or bypass safer, purpose-built actions. This makes it easier for an agent to send unintended write operations or hit sensitive endpoints with broad effects using authenticated access.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal