No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by cocoyes · MCP Server · ★ 183
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is zhizhi-agent-runtime safe to install? View the security audit →
zhizhi-agent-runtime 中文文档 Architecture and package boundaries Production-grade Go runtime for agents that plan, act, recover, and remain auditable. Version 1.0.7 adds a realtime duplex speech API, kept separate from ordinary LLM calls, plus a function-calling Doubao adapter. See Doubao realtime speech. Zhizhi is a model-agnostic execution layer for real applications. It turns ordinary Go functions into validated tools, builds dependency-safe plans, handles conditional branches and bounded replanning, and makes side effects explicit. Star History <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?rep
| Stars | 183 |
| Forks | 15 |
| Language | Go |
| Category | MCP Server |
| License | MIT |
| Quality Score | 68.9622730724624/100 |
| Last Updated | 2026-09-16 |
| Created | 2026-08-31 |
| Platforms | go, mcp |
| Est. Tokens | ~19k |
These tools work well together with zhizhi-agent-runtime for enhanced workflows:
Explore other popular mcp server tools:
zhizhi-agent-runtime is A model-agnostic, stateless Go agent runtime featuring dual-IR planning, dependency-aware batch scheduling, capability-driven MCP/tool orchestration, policy-based failure recovery, conditional replann. It is categorized as a MCP Server with 183 GitHub stars.
zhizhi-agent-runtime is primarily written in Go.
You can find installation instructions and usage details in the zhizhi-agent-runtime GitHub repository at github.com/cocoyes/zhizhi-agent-runtime. The project has 183 stars and 15 forks, indicating an active community.
zhizhi-agent-runtime is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: