ager-to-orca

Warn

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of global tools from an external GitHub repository not belonging to a known trusted vendor. This action installs third-party code into the global environment. \n
  • Evidence: npx skills add https://github.com/stablyai/orca --skill orca-cli --global in SKILL.md.\n- [COMMAND_EXECUTION]: The skill invokes local Python scripts to perform data translation and validation, which execute in the user's environment. The contents of these scripts were not provided for analysis. \n
  • Evidence: python3 scripts/emit.py and python3 scripts/validate.py in SKILL.md.\n- [PROMPT_INJECTION]: The skill exhibits surface area for indirect prompt injection by processing external AGER/OKF AgentGraph bundles without defined security boundaries. \n
  • Ingestion points: AGER/OKF AgentGraph bundle identified by <AGER_ROOT> in SKILL.md.\n
  • Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the processing logic.\n
  • Capability inventory: Shell command execution via python3 and npx, along with file writing and project modification capabilities.\n
  • Sanitization: The skill mentions ager-validate for format integrity, but does not specify security-focused sanitization of user-provided graph content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 23, 2026, 08:34 PM
Security Audit — agent-trust-hub — ager-to-orca