orderly-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed for integration with Orderly Network, a legitimate omnichain trading infrastructure provider.
- [SAFE]: Sensitive session keys are stored in the workspace with restricted permissions (
0o600) to prevent unauthorized access. - [SAFE]: Network communications are directed to official Orderly Network and Starchild API endpoints for trade reporting and synchronization.
- [INDIRECT_PROMPT_INJECTION]: The skill handles data from external API sources.
- Ingestion points: Trade fill data is retrieved from Orderly Network API endpoints in
trade_sync.pyviafetch_private_fillsandfetch_public_fills. - Boundary markers: Data processing occurs within a standalone synchronization script; output is sent to a structured API endpoint rather than being directly interpolated into a natural language prompt.
- Capability inventory: The skill uses network capabilities for API interaction and file system writes for local key management.
- Sanitization: Untrusted external data is validated through JSON parsing and strict mapping to a predefined schema in
scripts/trade_sync.py.
Audit Metadata