skills/machamy/orca/orca-cli/Gen Agent Trust Hub

orca-cli

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local binary (orca, orca-ide, or orca-dev) to perform tasks such as managing worktrees and terminals. It includes a usability warning to avoid the GNOME Orca screen reader on Linux systems.
  • [PROMPT_INJECTION]: The skill uses the 'ORCA skills get orca-cli' command to load further instructions at runtime. This creates a surface for indirect prompt injection where the agent's behavior is influenced by the tool's output.
  • [DATA_EXFILTRATION]: The description mentions 'public artifact links' and 'sharing HTML/Markdown', which are standard features of the Orca ecosystem initiated by user requests rather than unauthorized exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:20 AM
Security Audit — agent-trust-hub — orca-cli