orderly-positions-tpsl

Pass

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill describes an interface that exposes an indirect prompt injection surface. \n- Ingestion points: External position and PnL data are fetched through usePositionStream and GET /v1/positions. \n- Boundary markers: Absent; no delimiters are used to wrap external data for the agent. \n- Capability inventory: High-impact trading actions are available, including closing positions (usePositionClose), adjusting leverage (useLeverage), and submitting TP/SL orders (useTPSLOrder). \n- Sanitization: Absent; no validation or sanitization of string data from the exchange is specified to prevent instruction injection.\n- [SAFE]: All external resources, including the @orderly.network/hooks SDK and REST API endpoints, are verified vendor resources belonging to the author, OrderlyNetwork.\n- [NO_CODE]: The skill consists entirely of markdown documentation and code examples; no local executable scripts or binaries are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 6, 2026, 05:58 PM