orderly-positions-tpsl
Pass
Audited by Gen Agent Trust Hub on Mar 6, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill describes an interface that exposes an indirect prompt injection surface. \n- Ingestion points: External position and PnL data are fetched through
usePositionStreamandGET /v1/positions. \n- Boundary markers: Absent; no delimiters are used to wrap external data for the agent. \n- Capability inventory: High-impact trading actions are available, including closing positions (usePositionClose), adjusting leverage (useLeverage), and submitting TP/SL orders (useTPSLOrder). \n- Sanitization: Absent; no validation or sanitization of string data from the exchange is specified to prevent instruction injection.\n- [SAFE]: All external resources, including the@orderly.network/hooksSDK and REST API endpoints, are verified vendor resources belonging to the author, OrderlyNetwork.\n- [NO_CODE]: The skill consists entirely of markdown documentation and code examples; no local executable scripts or binaries are included.
Audit Metadata