orderly-plugin-add
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and follow integration instructions from external plugin metadata, which could contain malicious prompts designed to hijack the agent's behavior.
- Ingestion points: The skill reads the
usagePromptandreadmefields from the output of theorderly-devkit view <pluginId>command in Step 2 ofSKILL.md. - Boundary markers: Absent. The instructions from the
usagePromptare treated as authoritative guidance without delimiters or warnings to ignore embedded instructions. - Capability inventory: The agent has the capability to modify project source code (React components), update
package.jsonmanifests, and execute shell commands likepnpm install. - Sanitization: Absent. There is no evidence of sanitization or validation performed on the external metadata before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill utilizes shell commands to interact with the project environment and external developer tools.
- Evidence: The skill uses
rg(ripgrep) to search for components,npx orderly-devkitto view plugin metadata, andpnpm installto manage dependencies. While these are standard development tasks, the use of user-provided plugin IDs in shell commands without explicit sanitization presents a potential surface for shell argument injection.
Audit Metadata