orca-cli
Warn
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill determines which local binary to run (
orca,orca-ide, ororca-dev) based on environment variables likeORCA_CLI_COMMANDandORCA_DEV_REPO_ROOTor system context. - [PROMPT_INJECTION]: The instructions mandate running
ORCA skills get orca-clito fetch the full guide. This is an indirect prompt injection surface where the agent's core instructions are provided by the output of a local tool, preventing static verification of the agent's complete behavior. - Ingestion points: Command output from
ORCA skills get orca-cliin SKILL.md. - Boundary markers: Absent; instructions from the tool are treated as authoritative without delimiters.
- Capability inventory: Terminal interaction, worktree management, and browser control as described in the frontmatter.
- Sanitization: Absent; the agent is expected to follow the retrieved guide directly.
Audit Metadata