orchestration
Warn
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions in
SOURCE.mdrecommend installing the skill globally vianpxfrom a third-party GitHub repository (https://github.com/stablyai/orca). - [COMMAND_EXECUTION]: The skill requires the execution of local binaries (
orca,orca-ide, ororca-dev) to perform orchestration tasks, status checks, and terminal management. - [DYNAMIC_EXECUTION]: The skill is designed as a 'discovery stub' that deliberately omits its full instruction set. It directs the agent to execute
ORCA skills get orchestrationat runtime to retrieve and load the 'full guide' into the session. This prevents static auditing of the complete behavioral instructions provided to the agent. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection via dynamically loaded content.
- Ingestion points: The agent context is updated with the stdout of the
ORCA skills get orchestrationcommand (as described inSKILL.md). - Boundary markers: There are no mentioned delimiters or safety preambles to distinguish the external binary's output from trusted system instructions.
- Capability inventory: The skill possesses capabilities to execute shell commands, manage terminals, and coordinate multi-agent tasks.
- Sanitization: The skill lacks any mechanism to validate or sanitize the instruction guide fetched from the binary output before it is processed by the model.
Audit Metadata