orca-per-workspace-env

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute a local binary based on environment variables or specific local paths. Specifically, it uses ORCA_CLI_COMMAND, ORCA_DEV_REPO_ROOT, or default names like orca-dev, orca-ide, and orca. If the environment variable ORCA_CLI_COMMAND is manipulated to point to a malicious script, the agent would execute it when attempting to load the guide.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the output of an external command (ORCA skills get orca-per-workspace-env) to define its own instructions. This represents a vulnerability surface where a compromised or malicious local tool could inject instructions into the agent's session.
  • Ingestion points: SKILL.md (execution of the command to load the guide)
  • Boundary markers: Absent; the command output is intended to be treated as a guide for the agent.
  • Capability inventory: The skill allows execution of subprocesses via the resolved ORCA command.
  • Sanitization: Absent; the skill relies on the output of the local command being authoritative and safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:53 AM
Security Audit — agent-trust-hub — orca-per-workspace-env