cas — security grade SAFE, quality 74/100

Security audit verdict: SAFE · quality 74/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by codingagentsystem · MCP Server · ★ 133

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is cas safe to install? View the security audit →

About cas

██████╗ █████╗ ███████╗ ██╔════╝██╔══██╗██╔════╝ ██║ ███████║███████╗ ██║ ██╔══██║╚════██║ ╚██████╗██║ ██║███████║ ╚═════╝╚═╝ ╚═╝╚══════╝ Multi-agent coding factory with persistent memory. Factory · Context System · Quick Start · Installation · Architecture · Contributing What is CAS? CAS is a multi-agent coding factory and persistent context system for AI agents. It has two core capabilities: Factory — A terminal UI that orchestrates multiple Claude Code instances working in parallel on the same codebase, with a supervisor agent coordinating worker agents across isolated git worktrees. Context System — An MCP server that gives agents persistent memory, task tracking, rules, and skills across sessions, backed by SQLite and full-text search. Factory Factory mode turns your terminal into a multi-agent coding operation. A supervisor agent breaks work into tasks while worker agents ex

aiai-orchestrationclaudeclaude-codeclicoding-assistantdeveloper-toolsfactory-modemcpmulti-agent

Quick Facts

Stars133
Forks17
LanguageRust
CategoryMCP Server
LicenseMIT
Quality Score73.9202889489829/100
Last Updated2026-03-12
Created2026-01-05
Platformsclaude-code, cli, mcp, rust
Est. Tokens~3347k

cas alternative? Top 6 similar tools

Looking for a cas alternative? If you're comparing cas with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • claude-code-open by kill136 · ⭐ 158

    Open source AI coding platform with Web IDE, multi-agent system, 37+ tools, MCP protocol. MIT licensed.

  • sandboxed.sh by Th0rgal · ⭐ 513

    Safe runtime for autonomous on-chain AI agents: isolated sandboxes, Library skills, encrypted secrets.

  • sudocode by sudocode-ai · ⭐ 292

    Lightweight agent orchestration dev tool that lives in your repo

  • holysheep-cli by holysheep123 · ⭐ 292

    🐑 One command to configure all AI coding tools — Claude Code, Codex, Gemini CLI, Cursor, Aider & more

  • gptree by travisvn · ⭐ 290

    A CLI tool to provide LLM context for coding projects by combining project files into a single text file (or c

  • deepcontext-mcp by Wildcard-Official · ⭐ 278

    DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Rust Agent Tools

Frequently Asked Questions

What is cas?

cas is Multi-agent orchestration for Claude Code. Persistent memory, tasks, rules, and skills that make AI agents actually coordinate.. It is categorized as a MCP Server with 133 GitHub stars.

What programming language is cas written in?

cas is primarily written in Rust. It covers topics such as ai, ai-orchestration, claude.

How do I install or use cas?

You can find installation instructions and usage details in the cas GitHub repository at github.com/codingagentsystem/cas. The project has 133 stars and 17 forks, indicating an active community.

What license does cas use?

cas is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to cas?

The top alternatives to cas on Agent Skills Hub include claude-code-open, sandboxed.sh, sudocode. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools