qwen-code — security grade SAFE, quality 74/100

Security audit verdict: SAFE · quality 74/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by QwenLM · MCP Server · ★ 28.3k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is qwen-code safe to install? View the security audit →

About qwen-code

An open-source AI agent that lives in your terminal. 中文 | Deutsch | français | 日本語 | Русский | Português (Brasil) 🎉 News (2026-02-16): Qwen3.5-Plus is now live! Sign in via Qwen OAuth to use it directly, or get an API key from [Alibaba Cloud ModelStudio](https://modelstudio.console.alibabacloud.com?tab=doc#/doc/?type=model&url=28409142&modelId=gro

agenticaiai-agentai-codingclicoding-agentdeveloper-toolsllmmcpqwen

Quick Facts

Stars28,285
Forks3,150
LanguageTypeScript
CategoryMCP Server
LicenseApache-2.0
Quality Score73.633934365614/100
Open Issues1621
Last Updated2026-10-03
Created2025-06-26
Platformscli, mcp, node
Est. Tokens~18k

Compatible Skills

These tools work well together with qwen-code for enhanced workflows:

  • gemini-cli — semantic(0.27)+complementary+same_lang+similar_pop+shared_platform (59%)
  • voltagent — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (57%)
  • mission-control — semantic(0.17)+complementary+same_lang+similar_pop+shared_platform (56%)
  • Chaterm — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (53%)
  • YC-Killer — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (52%)

qwen-code alternative? Top 6 similar tools

Looking for a qwen-code alternative? If you're comparing qwen-code with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • oh-my-pi by can1357 · ⭐ 34.2k

    ⌥ Coding agent with the IDE wired in. Built by Stencil Labs.

  • chatgpt-on-wechat by zhayujie · ⭐ 43.0k

    CowAgent是基于大模型的超级AI助理,能主动思考和任务规划、访问操作系统和外部资源、创造和执行Skills、拥有长期记忆并不断成长,比OpenClaw更轻量和便捷。同时支持微信、飞书、钉钉、企微、QQ、公众号、网页

  • composio by ComposioHQ · ⭐ 30.4k

    Composio powers 1000+ toolkits, tool search, context management, authentication, and a sandboxed workbench to

  • repomix by yamadashy · ⭐ 28.7k

    📦 Repomix is a powerful tool that packs your entire repository into a single, AI-friendly file. Perfect for w

  • plandex by plandex-ai · ⭐ 15.6k

    Open source AI coding agent. Designed for large projects and real world tasks.

  • ouroboros by Q00 · ⭐ 6.2k

    Agent OS: the agent gets smarter on its own. We just hold the line: Interview-gated, staged evaluation, budget

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is qwen-code?

qwen-code is An open-source AI coding agent that lives in your terminal.. It is categorized as a MCP Server with 28.3k GitHub stars.

What programming language is qwen-code written in?

qwen-code is primarily written in TypeScript. It covers topics such as agentic, ai, ai-agent.

How do I install or use qwen-code?

You can find installation instructions and usage details in the qwen-code GitHub repository at github.com/QwenLM/qwen-code. The project has 28.3k stars and 3150 forks, indicating an active community.

What license does qwen-code use?

qwen-code is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to qwen-code?

The top alternatives to qwen-code on Agent Skills Hub include oh-my-pi, chatgpt-on-wechat, composio. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools