skills/beita6969/scienceclaw/ordercli/Gen Agent Trust Hub

ordercli

Warn

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill triggers the installation of the ordercli tool from a non-official, third-party GitHub repository (steipete/ordercli) using either the Homebrew package manager or the Go compiler. Although the developer is well-known in specific communities, they are not on the established trusted vendor list.\n- [DATA_EXFILTRATION]: The skill includes functionality to access and extract sensitive information from the local system, including Chrome cookies via ordercli foodora cookies chrome and browser session profiles located at $HOME/Library/Application Support/ordercli/browser-profile. Access to these sensitive paths represents a high risk of data exposure.\n- [CREDENTIALS_UNSAFE]: The instructions guide the agent in handling authentication secrets, such as accepting passwords through standard input (--password-stdin) and utilizing sensitive environment variables like DELIVEROO_BEARER_TOKEN and DELIVEROO_COOKIE.\n- [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by ingesting untrusted data from Foodora and Deliveroo APIs (e.g., order history via ordercli foodora history show). It lacks explicit boundary markers or sanitization for this external content, while maintaining the capability to execute shell commands through the ordercli binary.\n- [COMMAND_EXECUTION]: The skill executes shell commands to perform actions such as reordering food, configuring account settings, and managing active delivery sessions, which involves the manipulation of user financial and personal data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 6, 2026, 11:31 PM
Security Audit — agent-trust-hub — ordercli