ordercli

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill triggers the installation of the ordercli binary from an external repository (github.com/steipete/ordercli) via Go or Homebrew.\n- [COMMAND_EXECUTION]: The skill relies on the execution of the ordercli command-line interface to interact with food delivery services.\n- [CREDENTIALS_UNSAFE]: The skill provides guidance on managing authentication, including providing passwords through standard input and importing session cookies from browser profiles to maintain active sessions.\n- [PROMPT_INJECTION]: The skill ingests data from external food delivery APIs (order history, restaurant names), which introduces an indirect prompt injection surface. Evidence: (1) Ingestion points: ordercli foodora history, ordercli foodora orders. (2) Boundary markers: None mentioned. (3) Capability inventory: Login and reordering. (4) Sanitization: None documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — ordercli