ordinal-cli

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides comprehensive instructions for executing the ordinal CLI tool. It describes command patterns for resource management (posts, ideas, labels), authentication via flags or environment variables, and discovery using help flags.
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface.
  • Ingestion points: The agent is instructed to read and process data from the CLI tool's output (JSON/table) and from local JSON files provided via the --body-file flag.
  • Boundary markers: The instructions do not define clear boundaries or ignore warnings for data ingested from these external sources.
  • Capability inventory: The agent can perform significant actions including modifying workspace data, managing webhooks, and interacting with external social media platforms via the CLI.
  • Sanitization: No explicit sanitization or validation logic is defined for data received from the CLI or external files before it is used in subsequent agent steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 02:50 PM
Security Audit — agent-trust-hub — ordinal-cli