maestro — security grade SAFE, quality 63/100

Security audit verdict: SAFE · quality 63/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by ReinaMacCredy · MCP Server · ★ 232

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is maestro safe to install? View the security audit →

About maestro

maestro Local-first harness for agent-built codebases. Humans steer, agents execute, maestro is the substrate. maestro is a single Rust binary that gives a coding agent a durable place to work. Every unit of work, what is being built, who is doing it, and the proof it was done, lives as plain files under in your repo. No daemon, no hidden service state, no cloud. The agent runs the lifecycle through the CLI; you review the artifacts. Why Coding agents are fast but forgetful. They lose the thread across sessions, ship work that was never verified, and leave no trail you can audit. maestro fixes that by making the work itself durable and gated: A feature carries the product contract and walks a real lifecycle: . A task cannot be called done until its claim is backed by proof that you can read. QA (baseline plus slices) gates a ship, so "shipped" means covered, not just compiled. Decisions are recorded as files, so the why survives the agent's context window. Everything is repo-local and reviewable in a diff. Lifecycle Features, tasks, and harness improvements each w

agent-harnessagent-skillsai-agentsai-coding-agentsclaude-codeclicodexconductorharness-engineeringharness-os

Quick Facts

Stars232
Forks23
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score63.3496461717217/100
Open Issues6
Last Updated2026-09-28
Created2025-12-19
Platformsclaude-code, cli, codex, mcp, node
Est. Tokens~21k

maestro alternative? Top 6 similar tools

Looking for a maestro alternative? If you're comparing maestro with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • memorix by AVIDS2 · ⭐ 825

    Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Wi

  • hcom by aannoo · ⭐ 530

    Let AI agents message, watch, and spawn each other across terminals. Claude Code, Codex, Antigravity CLI, Curs

  • entroly by juyterman1000 · ⭐ 471

    Cut AI context cost without trusting the compressor. Every reduction is reversible, byte-exact recoverable, an

  • lacp by 0xNyk · ⭐ 299

    Local-first policy, evidence, memory, and recovery controls for Claude, Codex, Hermes, and other CLI coding ag

  • ClawMem by yoloshii · ⭐ 212

    On-device memory layer for AI agents. Claude Code, OpenClaw and Hermes. Hooks + MCP server + hybrid RAG search

  • claude-emporium by Vvkmnn · ⭐ 82

    🏛 [UNDER CONSTRUCTION] A (roman) claude plugin marketplace

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is maestro?

maestro is Local-first coordination for human and agent work: durable work, decisions, dispatches, evidence, and prompt-first methods, powered by TypeScript and Bun.. It is categorized as a MCP Server with 232 GitHub stars.

What programming language is maestro written in?

maestro is primarily written in TypeScript. It covers topics such as agent-harness, agent-skills, ai-agents.

How do I install or use maestro?

You can find installation instructions and usage details in the maestro GitHub repository at github.com/ReinaMacCredy/maestro. The project has 232 stars and 23 forks, indicating an active community.

What license does maestro use?

maestro is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to maestro?

The top alternatives to maestro on Agent Skills Hub include memorix, hcom, entroly. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools