orchestration
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
orcaCLI for managing terminals and executing shell commands within them, such as launching other agent CLIs.- [PROMPT_INJECTION]: The skill describes a 'preamble injection' feature where a coordinator agent sends instructions and task specifications to worker agents. This is a legitimate feature of the orchestration system for structured communication between agents.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface where the agent is instructed to ingest data from other terminals throughorca orchestration check(messaging) andorca terminal read(terminal output buffer). This data is then used to influence subsequent agent actions. Ingestion points:orca orchestration checkandorca terminal read(SKILL.md). Capability inventory:orca terminal create,orca terminal send, andorca orchestration run(SKILL.md). Boundary markers: Preamble injection suggests a structured communication format, but explicit delimiters for external content are not detailed. Sanitization: No explicit sanitization, validation, or filtering of the ingested inter-agent messages or terminal output is described in the skill instructions.
Audit Metadata