orderly-plugin-add
Warn
Audited by Socket on May 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent, but the skill relies on an unverified `orderly-devkit view` command and explicitly defers to plugin-authored `usagePrompt` instructions, creating indirect prompt-injection and supply-chain risk. No direct credential harvesting or exfiltration is present, so this is not malicious, but it exceeds low-risk documentation behavior.
Confidence: 84%Severity: 56%
Audit Metadata