ontoly-software-graph
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: No security issues detected. The skill provides clear instructions for using a specialized software analysis tool within a repository environment.- [COMMAND_EXECUTION]: The workflow involves executing the "ontoly" CLI to build a software graph from the local repository. This is an expected and functional behavior for the described use cases.- [PROMPT_INJECTION]: The skill ingests data from the repository being analyzed, creating an indirect prompt injection surface. 1. Ingestion points: Repository source files and SoftwareGraph.json. 2. Boundary markers: Absent; the agent is instructed to treat the graph as the source of truth. 3. Capability inventory: The skill can execute "ontoly" CLI commands. 4. Sanitization: No explicit sanitization or validation of the ingested repository content is mentioned in the workflow.
Audit Metadata