ordercli

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for managing sensitive authentication data, including using --password-stdin for login and referencing environment variables like DELIVEROO_BEARER_TOKEN and DELIVEROO_COOKIE for authentication.\n- [EXTERNAL_DOWNLOADS]: The skill metadata contains installation instructions for downloading the ordercli tool from external sources including Homebrew (steipete/tap/ordercli) and GitHub (github.com/steipete/ordercli).\n- [COMMAND_EXECUTION]: The skill relies on the execution of the ordercli binary, which allows the agent to interact with external food delivery services.\n- [DATA_EXFILTRATION]: The tool is designed to access and import sensitive browser data, specifically Chrome cookies and browser profiles ($HOME/Library/Application Support/ordercli/browser-profile), to bypass bot protection and manage sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 04:37 AM
Security Audit — agent-trust-hub — ordercli