No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by agent-team-foundation · Codex Skill · ★ 130
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is first-tree safe to install? View the security audit →
Open App · Get Started · How It Works · Quickstart · Discussions <img src="https://img.shields.io/g
| Stars | 130 |
| Forks | 33 |
| Language | TypeScript |
| Category | Codex Skill |
| License | Apache-2.0 |
| Quality Score | 68.0634927381577/100 |
| Open Issues | 329 |
| Last Updated | 2026-08-15 |
| Created | 2026-03-20 |
| Platforms | claude-code, cli, codex, node |
| Est. Tokens | ~16k |
These tools work well together with first-tree for enhanced workflows:
Looking for a first-tree alternative? If you're comparing first-tree with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
First-tree routes work to the right agent, gives it the same context your team has, and loops humans in only w
Local-first coordination for human and agent work: durable work, decisions, dispatches, evidence, and prompt-f
Cut AI context cost without trusting the compressor. Every reduction is reversible, byte-exact recoverable, an
Context engineering for coding agents - CLAUDE.md templates, mechanical enforcement, and a field guide to 20+
🥇 The strongest free web search plugin for DeepSeek Harness, and the search bridge for every model without na
The missing linter and lsp for AI coding assistants. Validate CLAUDE.md, AGENTS.md, SKILL.md, hooks, MCP. Plug
Explore other popular codex skill tools:
first-tree is First-tree routes work to the right agent, gives it the same context your team has, and loops humans in only when the rules say so. Lives in your GitHub. Open source.. It is categorized as a Codex Skill with 130 GitHub stars.
first-tree is primarily written in TypeScript. It covers topics such as ai-agents, claude-code, cli.
You can find installation instructions and usage details in the first-tree GitHub repository at github.com/agent-team-foundation/first-tree. The project has 130 stars and 33 forks, indicating an active community.
first-tree is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to first-tree on Agent Skills Hub include first-tree, maestro, entroly. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: