orca-cli
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local binary (
orca,orca-dev, ororca-ide). It provides a resolution strategy based on environment variables (ORCA_CLI_COMMAND,ORCA_DEV_REPO_ROOT) and the operating environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingests dynamic instructions from the output of the CLI command
ORCA skills get orca-clito update the agent's capabilities and guidance. 1. Ingestion points: The output of theORCA skills get orca-clicommand is ingested as instructional context for the agent. 2. Boundary markers: None specified. 3. Capability inventory: Execution of Orca CLI commands to manage worktrees, terminals, repositories, and browser interactions. 4. Sanitization: None. The skill relies on the integrity of the local Orca installation.
Audit Metadata