skills/stablyai/orca/orca-cli/Gen Agent Trust Hub

orca-cli

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local binary (orca, orca-dev, or orca-ide). It provides a resolution strategy based on environment variables (ORCA_CLI_COMMAND, ORCA_DEV_REPO_ROOT) and the operating environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests dynamic instructions from the output of the CLI command ORCA skills get orca-cli to update the agent's capabilities and guidance. 1. Ingestion points: The output of the ORCA skills get orca-cli command is ingested as instructional context for the agent. 2. Boundary markers: None specified. 3. Capability inventory: Execution of Orca CLI commands to manage worktrees, terminals, repositories, and browser interactions. 4. Sanitization: None. The skill relies on the integrity of the local Orca installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:39 PM
Security Audit — agent-trust-hub — orca-cli