orderly-plugin-add

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the skill relies on an unverified `orderly-devkit view` command and explicitly defers to plugin-authored `usagePrompt` instructions, creating indirect prompt-injection and supply-chain risk. No direct credential harvesting or exfiltration is present, so this is not malicious, but it exceeds low-risk documentation behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 4, 2026, 07:24 AM
Package URL
pkg:socket/skills-sh/OrderlyNetwork%2Forderly-skills%2Forderly-plugin-add%2F@49f62995baad7d43eb4d4845591f73a7b241bb82