ordercli
Fail
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill metadata specifies installation commands for
orderclifrom a personal GitHub account (steipete/ordercli) via Homebrew and Go. These sources are not associated with a trusted organization or well-known service.\n- [COMMAND_EXECUTION]: The skill's primary functionality is dependent on the execution of theorderclibinary. Executing unverified third-party tools poses a risk of arbitrary command execution if the binary or repository is compromised.\n- [CREDENTIALS_UNSAFE]: The skill provides instructions for handling sensitive authentication data, including passing passwords via stdin and utilizing environment variables for bearer tokens (e.g.,DELIVEROO_BEARER_TOKEN), which can lead to credential exposure.\n- [DATA_EXFILTRATION]: The skill guides the agent to useordercli foodora cookies chrome, a command that extracts session cookies directly from the user's Chrome browser profile. This programmatic access to sensitive session data constitutes a high risk of account hijacking.\n- [PROMPT_INJECTION]: The skill processes external order data from delivery service APIs, creating a surface for indirect prompt injection. 1. Ingestion points: Tool outputs fromordercli foodora historyandordercli foodora orders(SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Execution of shell commands via theorderclitool. 4. Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata