skills/marcioaltoe/skills/onioncry/Gen Agent Trust Hub

onioncry

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill guides the agent in running the onioncry CLI to perform various tasks such as checking architectural boundaries, explaining file classifications, and generating dependency graphs. These operations are standard for development tooling and are executed within the context of the user's local repository.
  • [EXTERNAL_DOWNLOADS]: Documentation describes how to obtain the onioncry binary through well-known official package registries using standard package managers such as npm, bun, and cargo.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill processes project source code and configuration files to generate reports for the agent. However, this is inherent to the tool's primary purpose as a code analyzer.
  • Ingestion points: Local source files and configuration files (e.g., .onioncryrc.jsonc, tsconfig.json).
  • Boundary markers: The reports include a versioned footer completeness marker to help the agent detect truncated output.
  • Capability inventory: The agent has capabilities for shell command execution and local file writes (initialization of config files).
  • Sanitization: The skill instructions do not specify explicit sanitization, relying on the deterministic nature of the CLI output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 05:24 PM
Security Audit — agent-trust-hub — onioncry