agent-toolkit — security grade SAFE, quality 44/100

Security audit verdict: SAFE · quality 44/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by datacommonsorg · MCP Server · ★ 139

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is agent-toolkit safe to install? View the security audit →

About agent-toolkit

Data Commons Agent Toolkit This repo contains MCP tools and sample agents for fetching public information from Data Commons. User-facing documentation is at . MCP Server Data Commons MCP Server package PyPI: datacommons-mcp Sample agents Data Commons sample agents

Quick Facts

Stars139
Forks36
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score44.2634315357794/100
Open Issues27
Last Updated2026-09-15
Created2025-06-26
Platformsmcp, python
Est. Tokens~13k

Compatible Skills

These tools work well together with agent-toolkit for enhanced workflows:

  • SciToolAgent — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (53%)
  • investor-agent — semantic(0.21)+complementary+same_lang+similar_pop+shared_platform (52%)
  • agent-second-brain — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (52%)
  • CntxtPY — semantic(0.18)+complementary+same_lang+similar_pop+shared_platform (51%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is agent-toolkit?

agent-toolkit is Tools and agents for interacting with the Data Commons Knowledge Graph using the Model Context Protocol (MCP).. It is categorized as a MCP Server with 139 GitHub stars.

What programming language is agent-toolkit written in?

agent-toolkit is primarily written in Python.

How do I install or use agent-toolkit?

You can find installation instructions and usage details in the agent-toolkit GitHub repository at github.com/datacommonsorg/agent-toolkit. The project has 139 stars and 36 forks, indicating an active community.

What license does agent-toolkit use?

agent-toolkit is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools