orca-cli
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute local binaries including
orca,orca-ide, andorca-devbased on environment variables and session context. - [INDIRECT_PROMPT_INJECTION]: The skill uses a dynamic loading pattern where the actual usage guide is fetched from command output at runtime, creating a potential injection vector. \n- Ingestion points: The agent is instructed to run
ORCA skills get orca-cliand treat the output as the authoritative guide for subsequent actions. \n- Boundary markers: No explicit boundary markers or instructions to disregard embedded commands in the output are provided. \n- Capability inventory: The skill grants the agent capabilities to manage file systems (worktrees), terminals, and browser sessions through shell commands. \n- Sanitization: There is no evidence of sanitization or structural validation performed on the retrieved content before it is incorporated into the agent's context.
Audit Metadata