No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by alicankiraz1 · Codex Skill · ★ 185
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is CodexQB safe to install? View the security audit →
CodexQB Repo-aware planning for Codex. CodexQB turns a project repository into a durable planning package: main plan, existing-project autopsy, phase sub-plans, QA audit, and a gated implementation handoff. CodexQB is a Codex plugin that installs the skill. It is built for software, AI, infrastructure, security, and automation projects where planning needs to be evidence-backed, reviewable, and ready for step-by-step execution. The current release is hardened for repository marketplace distribution: dependency-free , GitHub Actions validation, and tracked-file sanitized exports through . Why CodexQB Repo-aware intake: CodexQB inspects the current repository before asking questions, then proposes evidence-backed defaults for project name, intent, target end state, and constraints. Durable planning docs: Output is written under so long planning work survives context changes and can be reviewed like normal project documentation. Project Autopsy: Existing projects get a focused report covering modules, features, placeholders, technical debt, integration gaps, validation gaps, and readiness risks. Full phase decomposi
| Stars | 185 |
| Forks | 17 |
| Language | Python |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 70.3066088873862/100 |
| Open Issues | 3 |
| Last Updated | 2026-07-24 |
| Created | 2026-06-14 |
| Platforms | codex, python |
| Est. Tokens | ~15k |
These tools work well together with CodexQB for enhanced workflows:
Looking for a CodexQB alternative? If you're comparing CodexQB with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Repeatable agentic engineering. The workflow layer that turns AI coding agents into a disciplined factory: dur
Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server
Research pipelines as semantic execution units: each skill declares inputs/outputs, acceptance criteria, and g
The operations layer for agentic engineering — portable skills and contracts connecting intent, agents, softwa
Open-source 2D IDE for managing AI agents in native CLIs, terminal, gits, beads issues, and files across multi
WebCode is a browser-based AI coding platform that lets you remotely run CLI assistants like Claude Code and C
Explore other popular codex skill tools:
CodexQB is CodexQB is a Codex plugin for evidence-backed repo comprehension, planning, QA audit, and gated implementation handoffs.. It is categorized as a Codex Skill with 185 GitHub stars.
CodexQB is primarily written in Python. It covers topics such as codex, codex-plugin, planning.
You can find installation instructions and usage details in the CodexQB GitHub repository at github.com/alicankiraz1/CodexQB. The project has 185 stars and 17 forks, indicating an active community.
CodexQB is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to CodexQB on Agent Skills Hub include flow-next, Overture, research-units-pipeline-skills. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: