orderly-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
npxcommands to initialize the Orderly MCP server (@orderly.network/mcp-server) and to install skills from the vendor's repository (OrderlyNetwork/skills). - [EXTERNAL_DOWNLOADS]: The skill references multiple Node.js packages and GitHub repositories provided by the vendor (Orderly Network) for SDK and CLI functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill integrates with tools that search documentation and retrieve API information from external vendor-controlled sources.
- Ingestion points: Documentation search results from
orderly.networkand API metadata fromapi.orderly.orgvia MCP tools. - Boundary markers: None explicitly specified for the ingested content within the skill instructions.
- Capability inventory: Shell execution (npm, npx), and network requests via the integrated MCP tools.
- Sanitization: No specific sanitization logic for the ingested documentation content is described.
Audit Metadata