Graft — security grade SAFE, quality 65/100

Security audit verdict: SAFE · quality 65/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by NanoNets · MCP Server · ★ 4.8k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is Graft safe to install? View the security audit →

About Graft

Turbocharge Claude Code, Cursor, Codex, Gemini & every coding agent: faster, cheaper, with contextual understanding specific to your codebase. <img src="https://img.shields.io/badge/License-MIT-20C997?style=for-the-badge"

ai-agentsanthropicclaude-codeclicode-graphcodexcontext-engineeringcursordeveloper-toolsgemini

Quick Facts

Stars4,831
Forks423
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score65.0970472556691/100
Open Issues76
Last Updated2026-08-25
Created2026-07-03
Platformsclaude-code, cli, codex, gemini, mcp, node
Est. Tokens~23k

Compatible Skills

These tools work well together with Graft for enhanced workflows:

  • ai-maestro — semantic(0.21)+complementary+rare_topics+same_lang+similar_pop+shared_platform (62%)
  • soulforge — semantic(0.29)+complementary+same_lang+similar_pop+shared_platform (60%)
  • Empryo — semantic(0.29)+complementary+same_lang+similar_pop+shared_platform (60%)
  • 10x — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (58%)
  • openwolf — semantic(0.23)+complementary+same_lang+similar_pop+shared_platform (58%)

Graft alternative? Top 6 similar tools

Looking for a Graft alternative? If you're comparing Graft with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Unity-MCP by IvanMurzak · ⭐ 4.3k

    AI Skills, MCP Tools, and CLI for Unity Engine. Full AI develop and test loop. Use cli for quick setup. Effici

  • antigravity-workspace-template by study8677 · ⭐ 1.3k

    Give Claude Code, Cursor, Codex CLI a ChatGPT for your codebase. Multi-agent knowledge engine, grounded Q&A wi

  • ai-guide by liyupi · ⭐ 19.8k

    程序员鱼皮的 AI 资源大全 + Vibe Coding 零基础教程,分享 OpenClaw 保姆级教程、大模型玩法(DeepSeek / GPT / Gemini / Claude / GLM)、最新 AI 资讯、Pr

  • code-graph-rag by vitali87 · ⭐ 5.2k

    The ultimate RAG for your monorepo. Query, understand, and edit multi-language codebases with the power of AI

  • pilot-shell by maxritter · ⭐ 2.1k

    Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software

  • unity-mcp by CoplayDev · ⭐ 14.3k

    Unity MCP acts as a bridge between AI assistants and your Unity Editor. Give your LLM tools to manage assets,

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is Graft?

Graft is Turbocharge Claude Code, Cursor, Codex, Gemini & every coding agent: faster, cheaper, with contextual understanding specific to your codebase.. It is categorized as a MCP Server with 4.8k GitHub stars.

What programming language is Graft written in?

Graft is primarily written in TypeScript. It covers topics such as ai-agents, anthropic, claude-code.

How do I install or use Graft?

You can find installation instructions and usage details in the Graft GitHub repository at github.com/NanoNets/Graft. The project has 4.8k stars and 423 forks, indicating an active community.

What license does Graft use?

Graft is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to Graft?

The top alternatives to Graft on Agent Skills Hub include Unity-MCP, antigravity-workspace-template, ai-guide. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools