orca-cli
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of the
orcacommand-line utility and its environment-specific variants (orca-ide,orca-dev). These commands are used to interact with worktrees, terminals, and system processes. - [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern where the agent is instructed to fetch its core operating instructions from the output of a local command (
ORCA skills get orca-cli). This creates a surface where the tool's output could potentially include instructions that influence agent behavior. - Ingestion points: The output of the
ORCA skills get orca-clicommand as described inSKILL.md. - Boundary markers: Absent; the instructions direct the agent to load and follow the full guide directly from the command output.
- Capability inventory: The skill provides access to terminal management (
ORCA terminal list), worktree state (ORCA worktree ps), and browser control. - Sanitization: Absent; the agent is instructed to rely on the version-matched guide provided by the binary.
- [DYNAMIC_EXECUTION]: The skill uses a dynamic approach to instruction loading by fetching its own manual at runtime from the
orcaexecutable, rather than relying on static documentation within the skill file.
Audit Metadata