orchestration

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes local system binaries including orca, orca-dev, and orca-ide to perform orchestration and terminal control tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill utilizes a dynamic instruction loading pattern (File: SKILL.md) where it ingests data from ORCA skills get orchestration. Ingestion point: command output from the local binary. Boundary markers: Absent. Capability inventory: shell execution, terminal control, and browser automation via orca-cli. Sanitization: Absent. This architecture keeps instructions synchronized with the tool version but creates a runtime surface for instruction ingestion.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses local environment variables ORCA_CLI_COMMAND and ORCA_DEV_REPO_ROOT to determine the execution path for the Orca binary within the current session.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:52 AM
Security Audit — agent-trust-hub — orchestration