skills/stablyai/orca/orchestration/Gen Agent Trust Hub

orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute specific binaries, including orca, orca-ide, and orca-dev, while utilizing environment variables such as ORCA_CLI_COMMAND for executable path resolution.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to load its primary instructions and task coordination guides dynamically from the output of a local shell command.\n
  • Ingestion points: Instruction data is ingested from the output of the ORCA skills get orchestration command call documented in SKILL.md.\n
  • Boundary markers: None identified; the agent is directed to treat the tool output as a definitive guide.\n
  • Capability inventory: Multi-agent task coordination, shell command execution, and worker supervision.\n
  • Sanitization: The guidance is sourced directly from a local binary provided by the vendor, minimizing the risk of untrusted external content injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:27 AM
Security Audit — agent-trust-hub — orchestration