Claude security directory

Commerce Layer Metrics

High risk

The Metrics Local MCP Server exposes a set of tools to interact with Commerce Layer [Metrics API](https://docs.commercelayer.io/metrics) and enables you to extract almost any kind of data information from your organization order, return, or cart history.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Can spend money on your behalf: This connector can complete purchases, bookings, or payments. A misused or hijacked prompt could result in real financial charges before you confirm.

Available capabilities

This add-on exposes 33 tools or capabilities.

  • orders-breakdown
  • orders-date-breakdown
  • orders-search
  • orders-stats
  • carts-breakdown
  • carts-date-breakdown
  • carts-search
  • carts-stats
  • returns-breakdown
  • returns-date-breakdown
  • returns-search
  • returns-stats
  • fbt
  • best-selling-products-by-market
  • customers_that_bought_a_specific_product
  • frequently-bought-together-products
  • last-carts-with-a-specific-product-from-a-specific-market
  • latest-archived-orders
  • latest-placed-orders-from-customers-with-specific-email-domains
  • number-of-products-per-order-by-country
  • orders-associated-with-a-specific-promotion
  • orders-by-bundle
  • orders-by-currency
  • orders-by-day

The interactive security report will load automatically.