No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by The-AI-Alliance · Agent Tool · ★ 56
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is cube-harness safe to install? View the security audit →
cube-harness Open source harness for building and evaluating AI agents using the CUBE Standard. CUBE Standard defines the benchmark protocol. cube-harness is the evaluation runtime: it runs agents against any CUBE-compatible benchmark, records trajectories, and scales execution with Ray. [!NOTE] cube-harness is in active development (alpha). Interfaces may change. We welcome early adopters and contributors who want to shape the framework, not just use it. See our Roadmap and Contributing Guide. Want to change the harness itself? Start with Changing cube-harness and the project Design Philosophy; the skill lets you check your own draft before anyone else reads it. Have a benchmark to contribute? Fill out this short form — no commitment required. Want to go deeper? Apply to join the core team. Quickstart Installation bash Clone the repository git clone https://g
| Stars | 56 |
| Forks | 9 |
| Language | Python |
| Category | Agent Tool |
| License | Apache-2.0 |
| Quality Score | 68.8987381419738/100 |
| Open Issues | 24 |
| Last Updated | 2026-08-11 |
| Created | 2025-11-21 |
| Platforms | python |
| Est. Tokens | ~15k |
These tools work well together with cube-harness for enhanced workflows:
Explore other popular agent tool tools:
cube-harness is Drive OSS standards and tools for data curation and evaluation creation for state of the art AI agents. It is categorized as a Agent Tool with 56 GitHub stars.
cube-harness is primarily written in Python.
You can find installation instructions and usage details in the cube-harness GitHub repository at github.com/The-AI-Alliance/cube-harness. The project has 56 stars and 9 forks, indicating an active community.
cube-harness is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: