skills/espetro/orca/orca-cli/Gen Agent Trust Hub

orca-cli

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute local binaries, specifically orca, orca-ide, or orca-dev, to manage worktrees, terminals, and internal automations.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses a dynamic instruction loading pattern where it fetches its primary usage guide from the output of the shell command ORCA skills get orca-cli at runtime. * Ingestion points: The output of ORCA skills get orca-cli is consumed as active instructions in SKILL.md. * Boundary markers: The skill lacks explicit delimiters or instructions to ignore potential commands embedded within the dynamic tool output. * Capability inventory: The agent is granted capabilities to execute shell commands, manage worktrees, and control an embedded browser. * Sanitization: There is no evidence of output validation or sanitization before the agent interprets the CLI output as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 09:39 AM
Security Audit — agent-trust-hub — orca-cli