No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Da7-Tech · Codex Skill · ★ 108
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is SureForge safe to install? View the security audit →
SureForge An instruction-only Agent Skill for complex work. It tells an AI agent to research before it asks, ask before it plans, plan before it builds, verify before it delivers, and to get an independent review before it calls anything done. Version 1.0.0. MIT license. Maintained by Da7-Tech. Why this exists Agents fail in predictable ways on big tasks. They start building before the request is understood. They treat a skipped question as a yes. They check a sample and call it complete. They re-read their own work and call it a review. They run out of review rounds and ship anyway. SureForge is the working procedure that grew out of dealing with exactly those failures, written down so an agent can follow it. The pattern behind it is simple: the time spent understanding, planning, and checking up front is far less than the time spent redoing work, patching it, and re-checking it by hand afterwards. Fewer do-overs means fewer tokens over the life of a task, less of your attention spent on review, and work that is right the first time far more often. It is plain text: a short entry point plus reference files the agent loads when it needs them.
| Stars | 108 |
| Forks | 12 |
| Language | Python |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 69.2366996454525/100 |
| Open Issues | 2 |
| Last Updated | 2026-09-09 |
| Created | 2026-09-09 |
| Platforms | claude-code, codex, python |
| Est. Tokens | ~11k |
Looking for a SureForge alternative? If you're comparing SureForge with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Hand off tasks to Devin — a plugin/skill for Claude Code, Codex, Cursor, and any coding agent
🚀 170+ pre-built skills for Claude Code, Cursor, Codex & 14+ AI tools. Stop re-teaching your AI the same thin
Local-first coordination for human and agent work: durable work, decisions, dispatches, evidence, and prompt-f
Turns AI agents from chaotic code generators into disciplined engineers. 12-stage workflow from research to pr
Skills for AI coding agents — Laravel, PHP, React, TypeScript, testing, security, and code quality.
Graph-based long-term memory skill for AI (LLM) coding agents — faster context, fewer tokens, safer refactors
Explore other popular codex skill tools:
SureForge is Agent Skill for complex work: research before asking, ask before planning, plan before building, verify before delivering, independent review before calling it done. Plain text, no runtime.. It is categorized as a Codex Skill with 108 GitHub stars.
SureForge is primarily written in Python. It covers topics such as agent-skills, ai-agents, claude-code.
You can find installation instructions and usage details in the SureForge GitHub repository at github.com/Da7-Tech/SureForge. The project has 108 stars and 12 forks, indicating an active community.
SureForge is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to SureForge on Agent Skills Hub include devin-handoff, ai-workflow, maestro. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: