orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute specific binaries, including
orca,orca-ide, andorca-dev, while utilizing environment variables such asORCA_CLI_COMMANDfor executable path resolution.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to load its primary instructions and task coordination guides dynamically from the output of a local shell command.\n - Ingestion points: Instruction data is ingested from the output of the
ORCA skills get orchestrationcommand call documented inSKILL.md.\n - Boundary markers: None identified; the agent is directed to treat the tool output as a definitive guide.\n
- Capability inventory: Multi-agent task coordination, shell command execution, and worker supervision.\n
- Sanitization: The guidance is sourced directly from a local binary provided by the vendor, minimizing the risk of untrusted external content injection.
Audit Metadata