orca-emulator-android

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute a local CLI tool (orca, orca-ide, or orca-dev) to perform Android device management tasks such as booting AVDs, installing apps, and interacting with the user interface via shell commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources that could be used to inject malicious instructions into the agent's context.
  • Ingestion points: Output from the ORCA skills get command (which provides usage guidelines), device accessibility trees, and system logs (logcat).
  • Boundary markers: The instructions do not define specific delimiters or "ignore" instructions to prevent the agent from obeying commands that might be embedded in the tool output or device data.
  • Capability inventory: The agent is granted the ability to execute shell commands for device control, including app installation, hardware button triggers, and runtime permission management.
  • Sanitization: No sanitization, escaping, or filtering of the external tool output or device logs is described in the discovery stub.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 10:38 AM