No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by buildkite · Agent Tool · ★ 77
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is buildkite-agent-metrics safe to install? View the security audit →
Buildkite Agent Metrics A command-line tool for collecting Buildkite agent metrics, focusing on enabling auto-scaling. Currently AWS Cloudwatch, StatsD, Prometheus, Stackdriver, New Relic, and OpenTelemetry are supported. Installing The latest binary is available from Github Releases. Container images We also publish Docker Images to Amazon Public ECR. These are based on Alpine Linux. You can run the container with a Docker CLI command such as: AWS Lambdas We also publish an AWS Lambda to S3 in region us-east-1. Each version is published to and is also available from Github Releases as . Example shell aws lambda create-function \ --function-name buildkite-agent-metrics
| Stars | 77 |
| Forks | 64 |
| Language | Go |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 65.4487220166965/100 |
| Open Issues | 22 |
| Last Updated | 2026-09-18 |
| Created | 2016-04-07 |
| Platforms | go |
| Est. Tokens | ~19k |
These tools work well together with buildkite-agent-metrics for enhanced workflows:
Explore other popular agent tool tools:
buildkite-agent-metrics is A command-line tool (and Lambda) for collecting Buildkite agent metrics. It is categorized as a Agent Tool with 77 GitHub stars.
buildkite-agent-metrics is primarily written in Go.
You can find installation instructions and usage details in the buildkite-agent-metrics GitHub repository at github.com/buildkite/buildkite-agent-metrics. The project has 77 stars and 64 forks, indicating an active community.
buildkite-agent-metrics is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: