orderly-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run npx commands to initialize the Orderly MCP server (@orderly.network/mcp-server) and to install skills from the vendor's repository (OrderlyNetwork/skills).
  • [EXTERNAL_DOWNLOADS]: The skill references multiple Node.js packages and GitHub repositories provided by the vendor (Orderly Network) for SDK and CLI functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill integrates with tools that search documentation and retrieve API information from external vendor-controlled sources.
  • Ingestion points: Documentation search results from orderly.network and API metadata from api.orderly.org via MCP tools.
  • Boundary markers: None explicitly specified for the ingested content within the skill instructions.
  • Capability inventory: Shell execution (npm, npx), and network requests via the integrated MCP tools.
  • Sanitization: No specific sanitization logic for the ingested documentation content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 01:22 PM
Security Audit — agent-trust-hub — orderly-onboarding