ager-to-orca
Warn
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of global tools from an external GitHub repository not belonging to a known trusted vendor. This action installs third-party code into the global environment. \n
- Evidence:
npx skills add https://github.com/stablyai/orca --skill orca-cli --globalinSKILL.md.\n- [COMMAND_EXECUTION]: The skill invokes local Python scripts to perform data translation and validation, which execute in the user's environment. The contents of these scripts were not provided for analysis. \n - Evidence:
python3 scripts/emit.pyandpython3 scripts/validate.pyinSKILL.md.\n- [PROMPT_INJECTION]: The skill exhibits surface area for indirect prompt injection by processing external AGER/OKF AgentGraph bundles without defined security boundaries. \n - Ingestion points: AGER/OKF AgentGraph bundle identified by
<AGER_ROOT>inSKILL.md.\n - Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the processing logic.\n
- Capability inventory: Shell command execution via
python3andnpx, along with file writing and project modification capabilities.\n - Sanitization: The skill mentions
ager-validatefor format integrity, but does not specify security-focused sanitization of user-provided graph content.
Audit Metadata