orca-emulator-android

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to identify and execute the Orca command-line interface. It provides logic to resolve the binary path using environment variables such as ORCA_CLI_COMMAND and ORCA_DEV_REPO_ROOT, falling back to orca-ide or orca based on the host operating system.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bootstrap mechanism that fetches an external instruction guide using the ORCA skills get command. While this represents a surface for ingesting external data, it is the primary intended function of the discovery stub.
  • Ingestion points: The instruction guide content retrieved via ORCA skills get orca-emulator-android is loaded into the agent's context (SKILL.md).
  • Boundary markers: The stub does not define specific boundary markers or 'ignore' instructions for the content it fetches.
  • Capability inventory: The skill environment provides access to the shell for executing Orca CLI commands and adb for Android device interaction.
  • Sanitization: No sanitization of the fetched guide content is performed within this discovery stub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:47 AM
Security Audit — agent-trust-hub — orca-emulator-android