orca-emulator-android
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute a local CLI tool (
orca,orca-ide, ororca-dev) to perform Android device management tasks such as booting AVDs, installing apps, and interacting with the user interface via shell commands. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources that could be used to inject malicious instructions into the agent's context.
- Ingestion points: Output from the
ORCA skills getcommand (which provides usage guidelines), device accessibility trees, and system logs (logcat). - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions to prevent the agent from obeying commands that might be embedded in the tool output or device data.
- Capability inventory: The agent is granted the ability to execute shell commands for device control, including app installation, hardware button triggers, and runtime permission management.
- Sanitization: No sanitization, escaping, or filtering of the external tool output or device logs is described in the discovery stub.
Audit Metadata