skills/solizardking/skills/ordercli/Gen Agent Trust Hub

ordercli

Fail

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill metadata specifies installation commands for ordercli from a personal GitHub account (steipete/ordercli) via Homebrew and Go. These sources are not associated with a trusted organization or well-known service.\n- [COMMAND_EXECUTION]: The skill's primary functionality is dependent on the execution of the ordercli binary. Executing unverified third-party tools poses a risk of arbitrary command execution if the binary or repository is compromised.\n- [CREDENTIALS_UNSAFE]: The skill provides instructions for handling sensitive authentication data, including passing passwords via stdin and utilizing environment variables for bearer tokens (e.g., DELIVEROO_BEARER_TOKEN), which can lead to credential exposure.\n- [DATA_EXFILTRATION]: The skill guides the agent to use ordercli foodora cookies chrome, a command that extracts session cookies directly from the user's Chrome browser profile. This programmatic access to sensitive session data constitutes a high risk of account hijacking.\n- [PROMPT_INJECTION]: The skill processes external order data from delivery service APIs, creating a surface for indirect prompt injection. 1. Ingestion points: Tool outputs from ordercli foodora history and ordercli foodora orders (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Execution of shell commands via the ordercli tool. 4. Sanitization: Absent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 12, 2026, 03:13 AM
Security Audit — agent-trust-hub — ordercli