orderly-plugin-submit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the orderly-devkit CLI tool to perform plugin validation (--dry-run) and final submission to the Marketplace API. These operations are gated by explicit user confirmation prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages the creation of a usagePrompt field in the plugin manifest. This field is intended to provide integration instructions for other AI agents, creating a potential attack surface for downstream poisoning. However, the skill mitigates this by enforcing human-in-the-loop validation, requiring the user to approve the full text or a diff before any data is written to the manifest file.
  • [DATA_EXPOSURE]: The skill accesses local project files including package.json and .orderly-manifest.json to resolve metadata such as the plugin name, repository URL, and tags for the submission payload. This access is necessary for the skill's stated purpose of publishing the plugin.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:27 AM
Security Audit — agent-trust-hub — orderly-plugin-submit