speckit-companion — security grade SAFE, quality 65/100

Security audit verdict: SAFE · quality 65/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by alfredoperez · Agent Tool · ★ 90

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is speckit-companion safe to install? View the security audit →

About speckit-companion

SpecKit Companion: review AI specs before they ship as broken code The spec workspace for developers running AI agents through Spec-Driven Development. Catch bad specs before they become bad code. What you get A spec workspace that turns AI-assisted, spec-driven development into something you can actually see and steer — without leaving VS Code: Catch bad specs before they become bad code. Review AI-generated specs the way you review pull requests: inline comments on specific lines, refine in place, and kill a vague requirement before it turns into 200 lines of wrong implementation. Watch every feature flow through its phases. Specify → Plan → Tasks → Done, each a one-click action, with live progress, a phase timeline, and an Activity overview of everything the spec tracks. Run leaner with Turbo. Opt into the companion spec-kit extension's trimmed pipeline — smaller specs, files-and-dependencies t

ai-toolsclaude-codedeveloper-toolsspec-driven-developmenttypescriptvscode-extension

Quick Facts

Stars90
Forks22
LanguageHTML
CategoryAgent Tool
LicenseMIT
Quality Score64.6292903528186/100
Open Issues13
Last Updated2026-09-22
Created2025-12-02
Platformsclaude-code, cli, gemini, vscode
Est. Tokens~28k

speckit-companion alternative? Top 6 similar tools

Looking for a speckit-companion alternative? If you're comparing speckit-companion with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-fusion by vinkius-labs · ⭐ 204

    MCP Fusion - The framework for AI-native MCP servers.

  • claude-historian-mcp by Vvkmnn · ⭐ 178

    📜 An MCP server for conversation history search and retrieval in Claude Code

  • argus by yessGlory17 · ⭐ 114

    Claude Code Agent Monitoring & Observability on VSCode

  • c0ntextKeeper by Capnjbrown · ⭐ 61

    Automatic context preservation for Claude Code. Never lose work to compaction again. 7 hooks, 187 semantic pat

  • claudepro-directory by JSONbored · ⭐ 217

    HeyClaude (formerly Claude Pro Directory) is a searchable collection of pre-built AI skills, agents, MCP serve

  • augments-mcp-server by augmnt · ⭐ 127

    Comprehensive MCP server providing real-time framework documentation access for Claude Code with intelligent c

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular HTML Agent Tools

Frequently Asked Questions

What is speckit-companion?

speckit-companion is VS Code extension for spec-driven development — manage specs, workflows, and steering docs for AI CLI tools (Claude Code, Gemini CLI, Copilot CLI). It is categorized as a Agent Tool with 90 GitHub stars.

What programming language is speckit-companion written in?

speckit-companion is primarily written in HTML. It covers topics such as ai-tools, claude-code, developer-tools.

How do I install or use speckit-companion?

You can find installation instructions and usage details in the speckit-companion GitHub repository at github.com/alfredoperez/speckit-companion. The project has 90 stars and 22 forks, indicating an active community.

What license does speckit-companion use?

speckit-companion is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to speckit-companion?

The top alternatives to speckit-companion on Agent Skills Hub include mcp-fusion, claude-historian-mcp, argus. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools