An agent harness for task automation — terminal, web, and API, on a model server you control
OnIt exposes a single tool (view_image_from_url) with minimal definition quality. The tool name is verb-first and reasonably clear, but the input schema is severely underdocumented, the 'url' parameter has a description but lacks examples, constraints, or guidance on acceptable formats. The tool description (23 characters) is below the 34-character minimum observed in production baselines and provides no context about return format, error handling, or when to invoke it. No output schema is documented, forcing LLMs to guess what fields will be returned. The tool lacks any parameter validation hints (e.g., must be HTTP/HTTPS, timeout behavior), error recovery guidance, or security notes about the external URL handling. While the tool itself is simple and the risk classification (READ_ONLY) is correct, the overall definition lacks the rigor expected for production use.
Analyzes an image from a given URL.
Tool description is only 23 characters ('Analyzes an image from a given URL.'). Production baseline is 194 chars (p10=34); descriptions under 20 chars score 0-20. This description lacks WHAT the tool returns, WHEN to use it, error behavior, and context for LLM selection.
No output schema documented. LLMs cannot determine what fields are returned (e.g., does it return text, structured labels, confidence scores?). This forces agents to hallucinate downstream field mappings.
Input parameter 'url' has minimal description ('The URL of the image to analyze.') with no constraints. Missing: protocol requirements (HTTP/HTTPS only?), size limits, timeout behavior, supported formats, or error guidance if the URL is unreachable.
No error handling guidance. What happens if the URL is malformed, unreachable, or points to a non-image? The description provides no recovery path for LLMs.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | D | 52 | 2025-06-18+ | v2 |
| 2026-03-09 | D | 59 | - | v1 |
No security or trust boundary guidance. The tool accepts arbitrary external URLs, does it validate the domain, enforce timeouts, or guard against SSRF? These details are critical for LLM reasoning about safe invocation.