orca-emulator-android
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to identify and execute the Orca command-line interface. It provides logic to resolve the binary path using environment variables such as
ORCA_CLI_COMMANDandORCA_DEV_REPO_ROOT, falling back toorca-ideororcabased on the host operating system. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a bootstrap mechanism that fetches an external instruction guide using the
ORCA skills getcommand. While this represents a surface for ingesting external data, it is the primary intended function of the discovery stub. - Ingestion points: The instruction guide content retrieved via
ORCA skills get orca-emulator-androidis loaded into the agent's context (SKILL.md). - Boundary markers: The stub does not define specific boundary markers or 'ignore' instructions for the content it fetches.
- Capability inventory: The skill environment provides access to the shell for executing Orca CLI commands and
adbfor Android device interaction. - Sanitization: No sanitization of the fetched guide content is performed within this discovery stub.
Audit Metadata