orderly-positions-tpsl

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements logic that ingests data from external financial API endpoints and provides capabilities to perform automated trading actions based on that data.\n
  • Ingestion points: Position data is retrieved from Orderly Network REST endpoints (/v1/positions, /v1/position/{symbol}) and the usePositionStream React hook.\n
  • Boundary markers: The provided implementation examples do not include explicit instructions or markers to the agent to distinguish between processed data and control instructions, nor warnings to ignore embedded content.\n
  • Capability inventory: The skill includes high-impact capabilities such as closing positions (closePosition), adjusting leverage (setLeverage), and submitting new orders (submit).\n
  • Sanitization: Data retrieved from the API is formatted for display (e.g., toFixed) but is not sanitized to prevent potential prompt injection if string-based metadata within the position object were manipulated.\n- [SAFE]: The skill uses official vendor-owned resources, specifically the @orderly.network/hooks SDK, and follows legitimate patterns for interacting with the Orderly Network platform. Requirements for API keys are appropriately documented as prerequisites without exposing or requesting hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 01:22 PM
Security Audit — agent-trust-hub — orderly-positions-tpsl