Ona
Enterprise platform running software engineering agents in isolated cloud environments.
OnaHow skills run on Ona
Ona, formerly Gitpod, runs agents inside disposable cloud development environments where they execute commands, change code, and raise pull requests against real repositories. Those environments hold source and credentials, which makes any skill loaded into them worth verifying first.
Skill security, assessed
Every public skill in our index is assessed by the Anomity Skill Intelligence engine against its real source: remote code execution, credential and data exfiltration, prompt injection, and unsafe installers.
Govern the skill layer on Ona
Scanning a skill before use tells you what it claims to do. Anomity's Endpoint Sensor sees what agents actually do at runtime: it discovers every skill, agent, and MCP server on the endpoint, and policy can allow, deny, or log the tool calls a skill triggers on Ona and every other agent. Violations route to your SIEM, Slack, email, or Jira with a queryable 90-day audit trail.
Book a 30-minute demo to see your own agent and skill inventory.




