ork-explore
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains explicit instructions to remain read-only and avoid modifying files ("Stay read-only", "Do not change files"), which prevents unauthorized modifications to the environment.
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from unfamiliar repositories, which is a known attack surface for indirect prompt injection.
- Ingestion points: Reads repository files and symbols to map codebase architecture (SKILL.md).
- Boundary markers: Lacks specific markers like XML tags, but requires the agent to "Cite files and symbols for every material claim" and "distinguish confirmed behavior from inference."
- Capability inventory: Accesses files via
ork_explorerorexplorertools, but is restricted to read-only actions. - Sanitization: No specific sanitization or filtering of untrusted data is described.
Audit Metadata