No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by davidmatousek · Claude Skill · ★ 87
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is tachi safe to install? View the security audit →
tachi Threat Modeling and Vulnerability Detection Harness for Claude Code. AI-Reasoning Scanner — STRIDE + AI + MAESTRO. Get started: Quick Start | Developer Guide (full walkthrough with worked examples) OWASP Coverage 50/50 across five frameworks — every catalogued threat in each framework has a tachi detection agent. [ML 202
| Stars | 87 |
| Forks | 21 |
| Language | Python |
| Category | Claude Skill |
| License | Apache-2.0 |
| Quality Score | 69.3760677936236/100 |
| Open Issues | 23 |
| Last Updated | 2026-08-13 |
| Created | 2026-03-21 |
| Platforms | claude-code, python |
| Est. Tokens | ~20k |
These tools work well together with tachi for enhanced workflows:
Looking for a tachi alternative? If you're comparing tachi with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
AI-powered security assessment SKILLS for your codebase. Multi-language (JS, Go, Python, Rust, Java, PHP, Ruby
Discover and compare open-source Agent Skills, tools & MCP servers — with quality scoring, trending analysis,
Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability
Security operations toolkit for AI coding agents. Give Claude Code 25+ skills to catch vulnerabilities, scan c
See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring befo
Explore other popular claude skill tools:
tachi is Threat modeling and AI-reasoning vulnerability detection harness for Claude Code — STRIDE + AI + MAESTRO. It is categorized as a Claude Skill with 87 GitHub stars.
tachi is primarily written in Python. It covers topics such as agentic-security, ai-security, attack-trees.
You can find installation instructions and usage details in the tachi GitHub repository at github.com/davidmatousek/tachi. The project has 87 stars and 21 forks, indicating an active community.
tachi is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to tachi on Agent Skills Hub include perseus, agent-skills-hub, Wazuh-MCP-Server. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: