gcode
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the OrcaSlicer command-line tool and a bundled Python script (
scripts/orca_presets.py) to perform its primary function of slicing models and configuring printer presets. These are standard operations for the skill's purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied 3D model files (e.g., .stl, .3mf, .obj) as input, which creates a potential surface for indirect instructions.
- Ingestion points: Model files provided by the user are read by OrcaSlicer and referenced in the preset configuration process.
- Boundary markers: No specific delimiters or instructions are present to ensure the agent ignores natural language content that might be embedded in the model files' metadata.
- Capability inventory: The skill can execute local binaries (orca-slicer, grep) and a local Python script for configuration and file management.
- Sanitization: The skill relies on the external slicer tool to handle file parsing and does not perform independent validation or sanitization of the input data.
Audit Metadata