Glyph — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by SidhuK · Agent Tool · ★ 179

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is Glyph safe to install? View the security audit →

About Glyph

Glyph Join the Glyph community Share feedback, ask questions, and help shape what comes next. Join us on Discord → Offline-first desktop note-taking application. Tauri 2 shell with a React 19 / TypeScript / Vite 8 frontend and a Rust backend. Data lives entirely on-disk in a per-space directory backed by SQLite and the local filesystem. No cloud sync, no server. Prerequisites Build & Run bash Install frontend dependencies pnpm install Development — frontend only (Vite on :1420) pnpm dev Development — full Tauri app (compiles Rust backend + launches Vite) pnpm tauri dev Production build (tsc + vite build; Tauri hooks run beforeBuildCommand) pnpm build Lint & format (Biome) pnp

ai-agentsai-assistantai-toolsknowledge-baseknowledge-managementmacmacosnote-takingnotes-apprust

Quick Facts

Stars179
Forks27
LanguageTypeScript
CategoryAgent Tool
LicenseAGPL-3.0
Quality Score67.5009072831941/100
Open Issues15
Last Updated2026-10-03
Created2026-01-30
Platformsnode
Est. Tokens~14k

Compatible Skills

These tools work well together with Glyph for enhanced workflows:

  • claude-desktop-extension-bear-notes — semantic(0.33)+complementary+same_lang+similar_pop+shared_platform (57%)
  • kavach — semantic(0.42)+rare_topics+same_lang+similar_pop+shared_platform (54%)
  • CodexMonitor — semantic(0.25)+complementary+rare_topics+same_lang+shared_platform (53%)

Glyph alternative? Top 6 similar tools

Looking for a Glyph alternative? If you're comparing Glyph with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Noteriv by thejacedev · ⭐ 82

    A fast, open-source markdown editor. Graph view, plugin API, themes, Git/WebDAV sync, AI MCP — built on Tauri

  • FlareMo by realchendahuang · ⭐ 295

    Cloudflare 原生团队知识库,提供 Memos 兼容 API 与 MCP 协议 / Cloudflare-native team knowledge base

  • kavach by LucidAkshay · ⭐ 253

    Tactical AI Workspace Monitor & EDR

  • ChatCrystal by ZengLiangYi · ⭐ 58

    Local-first AI PKM for coding conversations: import Claude Code/Cursor/Codex, distill notes, semantic search,

  • obsidian-mcp-server by cyanheads · ⭐ 685

    Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streama

  • cleanmymac-cli by MacPaw · ⭐ 601

    Clean Xcode, Docker, Homebrew, and developer caches, remove project and AI artifacts, analyze storage, and rec

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is Glyph?

Glyph is 📝 Glyph is a private desktop workspace for notes, documents, and ideas, with Markdown editing and built-in AI tools.. It is categorized as a Agent Tool with 179 GitHub stars.

What programming language is Glyph written in?

Glyph is primarily written in TypeScript. It covers topics such as ai-agents, ai-assistant, ai-tools.

How do I install or use Glyph?

You can find installation instructions and usage details in the Glyph GitHub repository at github.com/SidhuK/Glyph. The project has 179 stars and 27 forks, indicating an active community.

What license does Glyph use?

Glyph is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to Glyph?

The top alternatives to Glyph on Agent Skills Hub include Noteriv, FlareMo, kavach. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools