No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by doodledood · Codex Skill · ★ 73
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is manifest-dev safe to install? View the security audit →
manifest-dev Your agent builds the wrong thing, confidently. Not broken code — wrong code. It compiles. The tests pass. And it solves a problem you don't have, because the agent started typing before it understood what you meant. is the pushback. An adversarial thinking partner. It digs through your codebase on its own and presses on the question that decides the work. It refuses to touch code until you both know what "right" is, holds its position under pushback, and changes its mind when the evidence changes. A minute in, it has read your code and come back with the question you hadn't thought to ask. That first question is the fastest way to find out whether this tool is for you. Every skill here works standalone. Take what you want. No framework to adopt, nothing else to install. If you never run another command from this repo, /figure-
| Stars | 73 |
| Forks | 10 |
| Language | Python |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 69.7617119358062/100 |
| Open Issues | 7 |
| Last Updated | 2026-09-19 |
| Created | 2026-01-27 |
| Platforms | claude-code, cli, codex, python |
| Est. Tokens | ~15k |
These tools work well together with manifest-dev for enhanced workflows:
Looking for a manifest-dev alternative? If you're comparing manifest-dev with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
📼 Declarative AI agent environment manager, written in Rust
Just another desktop client for OpenCode 2. Manage projects, sessions, parallel agents, requests, and changes
Unified CLI for running AI coding agents in isolated containers. Includes built-in local metrics collection, H
Auto-review and iterate until quality work is delivered - a better alternative to ralph-claude-code. Switch be
Code from anywhere — Telegram bridge for AI coding agents (Claude Code, Codex, OpenCode, Pi, Gemini CLI, Amp).
DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent
Explore other popular codex skill tools:
manifest-dev is Skills for agentic coding CLIs: output you can ship with minimal review, on work you can tell was worth doing.. It is categorized as a Codex Skill with 73 GitHub stars.
manifest-dev is primarily written in Python. It covers topics such as agentic-coding, ai-agents, claude.
You can find installation instructions and usage details in the manifest-dev GitHub repository at github.com/doodledood/manifest-dev. The project has 73 stars and 10 forks, indicating an active community.
manifest-dev is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to manifest-dev on Agent Skills Hub include kasetto, palot, vibepod-cli. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: