orchestration
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local binaries (
orca,orca-ide,orca-dev) to perform orchestration tasks, status checks, and terminal management. This is the primary function of the skill and uses the vendor's own tooling. - [INDIRECT_PROMPT_INJECTION]: The skill fetches its full instruction set at runtime by running
ORCA skills get orchestration. This creates an ingestion point where the output of a shell command provides the agent's operating instructions. While this is a surface for potential injection if the binary's output were compromised, it is a design choice to ensure version compatibility between the agent and the orchestration engine. - Ingestion points: Output of
ORCA skills get orchestrationinSKILL.md. - Boundary markers: None specified in the stub; the agent is told to read the output and then run commands.
- Capability inventory: Task dispatch, shell command execution, terminal control, and browser automation via the Orca CLI.
- Sanitization: Not explicitly defined in the discovery stub.
Audit Metadata