orca-per-workspace-env
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute a local binary based on environment variables or specific local paths. Specifically, it uses
ORCA_CLI_COMMAND,ORCA_DEV_REPO_ROOT, or default names likeorca-dev,orca-ide, andorca. If the environment variableORCA_CLI_COMMANDis manipulated to point to a malicious script, the agent would execute it when attempting to load the guide. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the output of an external command (
ORCA skills get orca-per-workspace-env) to define its own instructions. This represents a vulnerability surface where a compromised or malicious local tool could inject instructions into the agent's session. - Ingestion points:
SKILL.md(execution of the command to load the guide) - Boundary markers: Absent; the command output is intended to be treated as a guide for the agent.
- Capability inventory: The skill allows execution of subprocesses via the resolved
ORCAcommand. - Sanitization: Absent; the skill relies on the output of the local command being authoritative and safe.
Audit Metadata