skills/zpyoung/orca/orca-ask/Gen Agent Trust Hub

orca-ask

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from a human user via the orca ask command, creating a potential surface for indirect prompt injection where the user could provide malicious instructions instead of expected data.
  • Ingestion points: User responses to orca ask (select, multiselect, text, number, date, confirm).
  • Boundary markers: The skill mentions that answers are returned in a "structured JSON answer envelope."
  • Capability inventory: The skill requires the ability to execute shell commands (orca skills get, orca ask, orca open) to interact with the environment.
  • Sanitization: The discovery stub does not explicitly detail sanitization or instructions to ignore embedded commands within the user's response.
  • [COMMAND_EXECUTION]: The skill instructs the agent to resolve and execute local binaries (orca, orca-dev, orca-ide). It includes safety checks to ensure the correct binary is used, specifically warning against the GNOME Orca screen reader on Linux systems and advising against falling back to different builds to prevent targeting unintended executables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:03 AM
Security Audit — agent-trust-hub — orca-ask