sage — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by avast · Claude Skill · ★ 119

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is sage safe to install? View the security audit →

About sage

Sage Safety for Agents — Agent Detection & Response for AI coding assistants Sage is a lightweight security layer that protects AI agents from executing dangerous actions. It intercepts tool calls — shell commands, URL fetches, file writes — and checks them against multiple threat detection layers before they run. Note: Sage may appear under a different product name (e.g., Norton Sage, Avast Sage) depending on how it was installed. See Branding for details. Key Features URL reputation — cloud-based detection of malware, phishing, and scam URLs Local heuristics — 300+ YAML-based threat patterns for dangerous commands, suspicious URLs, credential exposure, and obfuscation Prompt injection detection — two-tier defense (heuristics + fine-tuned ML model) against injected instructions in fetched content. See Prompt Injection Package supply-chain checks — registry existence, file reputation, and age analysis for npm/PyPI packages Plugin scanning — scans installed plugins for threats at session start AMSI integration — Windows Antimalware Scan Interface support (Windows + WSL via PowerShell interop; no-op on macOS and non

agentsaiclaude-codeclaude-code-plugincursor-aicursor-extensionopenclawsecurityvscode-extension

Quick Facts

Stars119
Forks5
LanguageTypeScript
CategoryClaude Skill
LicenseApache-2.0
Quality Score68.0347032077829/100
Open Issues3
Last Updated2026-03-10
Created2026-02-12
Platformsbrowser, claude-code, node, vscode
Est. Tokens~205k

sage alternative? Top 6 similar tools

Looking for a sage alternative? If you're comparing sage with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • sage by gendigitalinc · ⭐ 309

    Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. P

  • orchestkit by yonatangross · ⭐ 283

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • leash by strongdm · ⭐ 592

    Leash by StrongDM - take your AI agents for a walk

  • Auditor by TheAuditorTool · ⭐ 550

    Release channel for TheAuditor — see blog.theauditortool.com

  • claude-code-hooks by karanb192 · ⭐ 519

    🪝 Claude Code hooks + an installable plugin marketplace: safety, cost, observability, productivity.

  • hcom by aannoo · ⭐ 490

    Let AI agents message, watch, and spawn each other across terminals. Claude Code, Codex, Antigravity CLI, Curs

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is sage?

sage is Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.. It is categorized as a Claude Skill with 119 GitHub stars.

What programming language is sage written in?

sage is primarily written in TypeScript. It covers topics such as agents, ai, claude-code.

How do I install or use sage?

You can find installation instructions and usage details in the sage GitHub repository at github.com/avast/sage. The project has 119 stars and 5 forks, indicating an active community.

What license does sage use?

sage is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to sage?

The top alternatives to sage on Agent Skills Hub include sage, orchestkit, leash. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools