orderly-plugin-create
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches and executes the
@orderly.network/cliandorderly-devkitpackages from the npm registry usingnpxorpnpm. These are official tools provided by the vendor 'orderlynetwork'. - [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands to generate project structures, which involves running CLI tools with various flags.
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to command injection if user-provided strings for project names, IDs, or target paths contain malicious shell metacharacters.
- Ingestion points: User-supplied values for
--name,--id,--interceptor, and--targetinSKILL.md. - Boundary markers: None present to delimit user input from shell command structures.
- Capability inventory: Ability to execute shell commands via
npx,pnpm, andbashas defined inSKILL.md. - Sanitization: The skill refers to naming conventions in
reference.mdbut does not provide specific instructions for the agent to sanitize or escape inputs before command execution.
Audit Metadata