orca-cli
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute local binaries, specifically
orca,orca-ide, ororca-dev, to manage worktrees, terminals, and internal automations. - [INDIRECT_PROMPT_INJECTION]: The skill uses a dynamic instruction loading pattern where it fetches its primary usage guide from the output of the shell command
ORCA skills get orca-cliat runtime. * Ingestion points: The output ofORCA skills get orca-cliis consumed as active instructions inSKILL.md. * Boundary markers: The skill lacks explicit delimiters or instructions to ignore potential commands embedded within the dynamic tool output. * Capability inventory: The agent is granted capabilities to execute shell commands, manage worktrees, and control an embedded browser. * Sanitization: There is no evidence of output validation or sanitization before the agent interprets the CLI output as instructions.
Audit Metadata