skills/dcieslak19973/orca/orca-cli/Gen Agent Trust Hub

orca-cli

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill resolves and executes the orca CLI binary (or orca-ide/orca-dev) based on the environment. It uses system environment variables like ORCA_CLI_COMMAND and ORCA_DEV_REPO_ROOT to determine the correct executable path.
  • [PROMPT_INJECTION]: The skill implements a dynamic instruction loading pattern (Indirect Prompt Injection surface) where the agent is instructed to run 'ORCA skills get orca-cli' and follow the resulting guide. Ingestion points: SKILL.md instructs the agent to read and follow output from 'ORCA skills get orca-cli'. Boundary markers: Absent; the agent is told to treat the command output as the authoritative version-matched guide. Capability inventory: Shell command execution (subprocess calls) via the resolved binary. Sanitization: None; the agent is expected to parse and follow instructions provided by the tool's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:04 AM
Security Audit — agent-trust-hub — orca-cli