cayu — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by cayu-dev · Agent Tool · ★ 66

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is cayu safe to install? View the security audit →

About cayu

Cayu Cayu is a production agent runtime for building and operating AI agents in Python. A harness turns a model into an agent by supplying its context, tools, permissions, and execution logic. Cayu gives applications control of the full agent execution lifecycle: how context is assembled, models and tools are invoked, where agent code runs, how state is persisted, authority is governed, failures are recovered, and behavior is observed and evaluated. Cayu provides durable agent-runtime primitives including sessions, task dispatch, leased workers, resumable workflow steps, approvals, and recovery. Applications can use them directly without a separate workflow engine. Applications retain control of their UI, authentication, domain logic, and business workflows. Cayu is designed for agents that do consequential or long-running work. You compose its runtime primitives directly in your application. Why we built Cayu Cayu was extracted from the production runtime behind an agent-operated software factory that built and deployed thousands of business applications.

agentautonomous-agentsharnesslong-horizon-agentslong-running-agentsruntime

Quick Facts

Stars66
Forks49
LanguagePython
CategoryAgent Tool
LicenseApache-2.0
Quality Score65.5956328125141/100
Last Updated2026-09-16
Created2026-07-16
Platformspython
Est. Tokens~21k

cayu alternative? Top 6 similar tools

Looking for a cayu alternative? If you're comparing cayu with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • omnicoreagent by omnirexflora-labs · ⭐ 246

    Open Python agent harness for production AI apps: tools, MCP, memory, workspace, telemetry, subagents, backgro

  • Autono by vortezwohl · ⭐ 212

    A ReAct-Based Highly Robust Autonomous Agent (Harness) Framework.

  • nightshift by orwa-mahmoud · ⭐ 61

    Accountable long-running coding shifts for Cursor, Codex, and Claude Code. Safe autonomy, recovery, persistent

  • 5dive by 5dive-ai · ⭐ 60

    Run a company of AI agents on a server you own. Spin up named agents (claude, codex, pi…), put them on an org

  • awesome-loop-engineering by ChaoYue0307 · ⭐ 57

    🔁 Build reliable recurring AI-agent systems: 874 resources, 22 operational patterns, 22 loop contracts, 8 run

  • open-jet by L-Forster · ⭐ 50

    A terminal coding agent, and a Python SDK for embedding on-device models in your own apps.

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Python Agent Tools

Frequently Asked Questions

What is cayu?

cayu is Cayu is the runtime for long-horizon agents that need explicit environments, durable sessions, controlled tools, secrets boundaries, evals, and replay. It is categorized as a Agent Tool with 66 GitHub stars.

What programming language is cayu written in?

cayu is primarily written in Python. It covers topics such as agent, autonomous-agents, harness.

How do I install or use cayu?

You can find installation instructions and usage details in the cayu GitHub repository at github.com/cayu-dev/cayu. The project has 66 stars and 49 forks, indicating an active community.

What license does cayu use?

cayu is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to cayu?

The top alternatives to cayu on Agent Skills Hub include omnicoreagent, Autono, nightshift. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools