orca-cli

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using local Orca binaries (orca, orca-dev, orca-ide) to manage worktrees, terminals, and internal browser states.
  • [EXTERNAL_DOWNLOADS]: The documentation includes an installation example using npx to fetch skill content from a remote GitHub repository (https://github.com/stablyai/orca).
  • [REMOTE_CODE_EXECUTION]: The skill references the use of npx for adding the skill, which involves downloading and executing remote packages from a repository on a well-known service (GitHub).
  • [PROMPT_INJECTION]: The skill implements a dynamic instruction loading pattern by fetching its full guide from the output of the local Orca binary via the 'skills get' command.
  • Ingestion points: The full command reference is loaded into the agent's context from the output of the 'ORCA skills get orca-cli' shell command.
  • Boundary markers: The instructions do not define specific delimiters or validation steps for the dynamically loaded content.
  • Capability inventory: The Orca CLI provides capabilities for terminal interaction, file system management via worktrees, and browser control.
  • Sanitization: No sanitization or filtering of the binary's output is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 08:35 PM
Security Audit — agent-trust-hub — orca-cli