fff — security grade SAFE, quality 69/100

Security audit verdict: SAFE · quality 69/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by dmtrKovalenko · Agent Tool · ★ 10.8k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is fff safe to install? View the security audit →

About fff

A file search toolkit for humans and AI agents. Really fast. Typo-resistant path and content search, frequency-ranked file access, a background watcher, and a lightweight in-memory content index. Way faster than CLIs like ripgrep and fzf in any long-running process that searches more than once. Powers file search in opencode, nushell, and many more amazing projects! Originally started as Neovim plugin people loved, but it turned out that plenty of AI harnesses and code editors need the same thing: accurate, fast file search as a library. That is what fff is. Pick what you are interested in: MCP server Works with Claude Code, Codex, OpenCode, Cursor, Cline, and any MCP-capable client. Fewer grep roundtrips, less wasted context, faster answers. One-line install Linux / macOS: bash curl -L

bunffffilesearchfzfgrepluaneovimneovim-pluginnodejspython

Quick Facts

Stars10,776
Forks448
LanguageRust
CategoryAgent Tool
LicenseMIT
Quality Score68.7986065981801/100
Open Issues82
Last Updated2026-09-19
Created2025-07-31
Platformsrust
Est. Tokens~31k

Compatible Skills

These tools work well together with fff for enhanced workflows:

  • sidekick.nvim — semantic(0.47)+complementary+rare_topics+similar_pop (60%)
  • iwe — semantic(0.16)+complementary+rare_topics+same_lang+similar_pop+shared_platform (60%)
  • claudecode.nvim — semantic(0.46)+complementary+rare_topics+similar_pop (56%)
  • mcphub.nvim — semantic(0.33)+complementary+rare_topics+similar_pop (56%)

fff alternative? Top 6 similar tools

Looking for a fff alternative? If you're comparing fff with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • oh-my-pi by can1357 · ⭐ 32.0k

    ⌥ Coding agent with the IDE wired in

  • mcp-for-beginners by microsoft · ⭐ 17.3k

    This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cr

  • sidekick.nvim by folke · ⭐ 2.8k

    Your Neovim AI sidekick

  • cocoindex-code by cocoindex-io · ⭐ 2.7k

    A super light-weight embedded code search engine CLI (AST based) that just works - improves speed and efficie

  • cli by googleworkspace · ⭐ 31.0k

    Google Workspace CLI — one command-line tool for Drive, Gmail, Calendar, Sheets, Docs, Chat, Admin, and more.

  • gpt-researcher by assafelovic · ⭐ 29.2k

    An autonomous agent that conducts deep research on any data using any LLM providers

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Rust Agent Tools

Frequently Asked Questions

What is fff?

fff is The fastest and the most accurate file search SDK for AI agents, Neovim, Rust, C, Python, Bun and NodeJS. It is categorized as a Agent Tool with 10.8k GitHub stars.

What programming language is fff written in?

fff is primarily written in Rust. It covers topics such as bun, fff, filesearch.

How do I install or use fff?

You can find installation instructions and usage details in the fff GitHub repository at github.com/dmtrKovalenko/fff. The project has 10.8k stars and 448 forks, indicating an active community.

What license does fff use?

fff is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to fff?

The top alternatives to fff on Agent Skills Hub include oh-my-pi, mcp-for-beginners, sidekick.nvim. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools