orchestration

Warn

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions in SOURCE.md recommend installing the skill globally via npx from a third-party GitHub repository (https://github.com/stablyai/orca).
  • [COMMAND_EXECUTION]: The skill requires the execution of local binaries (orca, orca-ide, or orca-dev) to perform orchestration tasks, status checks, and terminal management.
  • [DYNAMIC_EXECUTION]: The skill is designed as a 'discovery stub' that deliberately omits its full instruction set. It directs the agent to execute ORCA skills get orchestration at runtime to retrieve and load the 'full guide' into the session. This prevents static auditing of the complete behavioral instructions provided to the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection via dynamically loaded content.
  • Ingestion points: The agent context is updated with the stdout of the ORCA skills get orchestration command (as described in SKILL.md).
  • Boundary markers: There are no mentioned delimiters or safety preambles to distinguish the external binary's output from trusted system instructions.
  • Capability inventory: The skill possesses capabilities to execute shell commands, manage terminals, and coordinate multi-agent tasks.
  • Sanitization: The skill lacks any mechanism to validate or sanitize the instruction guide fetched from the binary output before it is processed by the model.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 23, 2026, 08:34 PM
Security Audit — agent-trust-hub — orchestration