orca-cli
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using local Orca binaries (orca, orca-dev, orca-ide) to manage worktrees, terminals, and internal browser states.
- [EXTERNAL_DOWNLOADS]: The documentation includes an installation example using npx to fetch skill content from a remote GitHub repository (https://github.com/stablyai/orca).
- [REMOTE_CODE_EXECUTION]: The skill references the use of npx for adding the skill, which involves downloading and executing remote packages from a repository on a well-known service (GitHub).
- [PROMPT_INJECTION]: The skill implements a dynamic instruction loading pattern by fetching its full guide from the output of the local Orca binary via the 'skills get' command.
- Ingestion points: The full command reference is loaded into the agent's context from the output of the 'ORCA skills get orca-cli' shell command.
- Boundary markers: The instructions do not define specific delimiters or validation steps for the dynamically loaded content.
- Capability inventory: The Orca CLI provides capabilities for terminal interaction, file system management via worktrees, and browser control.
- Sanitization: No sanitization or filtering of the binary's output is performed before processing.
Audit Metadata