orderly-positions-tpsl
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements logic that ingests data from external financial API endpoints and provides capabilities to perform automated trading actions based on that data.\n
- Ingestion points: Position data is retrieved from Orderly Network REST endpoints (
/v1/positions,/v1/position/{symbol}) and theusePositionStreamReact hook.\n - Boundary markers: The provided implementation examples do not include explicit instructions or markers to the agent to distinguish between processed data and control instructions, nor warnings to ignore embedded content.\n
- Capability inventory: The skill includes high-impact capabilities such as closing positions (
closePosition), adjusting leverage (setLeverage), and submitting new orders (submit).\n - Sanitization: Data retrieved from the API is formatted for display (e.g.,
toFixed) but is not sanitized to prevent potential prompt injection if string-based metadata within the position object were manipulated.\n- [SAFE]: The skill uses official vendor-owned resources, specifically the@orderly.network/hooksSDK, and follows legitimate patterns for interacting with the Orderly Network platform. Requirements for API keys are appropriately documented as prerequisites without exposing or requesting hardcoded credentials.
Audit Metadata