orderly-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for integration with Orderly Network, a legitimate omnichain trading infrastructure provider.
  • [SAFE]: Sensitive session keys are stored in the workspace with restricted permissions (0o600) to prevent unauthorized access.
  • [SAFE]: Network communications are directed to official Orderly Network and Starchild API endpoints for trade reporting and synchronization.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles data from external API sources.
  • Ingestion points: Trade fill data is retrieved from Orderly Network API endpoints in trade_sync.py via fetch_private_fills and fetch_public_fills.
  • Boundary markers: Data processing occurs within a standalone synchronization script; output is sent to a structured API endpoint rather than being directly interpolated into a natural language prompt.
  • Capability inventory: The skill uses network capabilities for API interaction and file system writes for local key management.
  • Sanitization: Untrusted external data is validated through JSON parsing and strict mapping to a predefined schema in scripts/trade_sync.py.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — orderly-onboarding