sage — security grade SAFE, quality 67/100

Security audit verdict: SAFE · quality 67/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by gendigitalinc · Codex Skill · ★ 309

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is sage safe to install? View the security audit →

About sage

Sage Safety for Agents — Agent Detection & Response for AI coding assistants Sage is a lightweight security layer that protects AI agents from executing dangerous actions. It intercepts tool calls — shell commands, URL fetches, file writes — and checks them against multiple threat detection layers before they run. Note: Sage may appear under a different product name (e.g., Norton Sage, Avast Sage) depending on how it was installed. See Branding for details. Key Features URL reputation — cloud-based detection of malware, phishing, and scam URLs Local heuristics — 300+ YAML-based threat patterns for dangerous commands, suspicious URLs, credential exposure, and obfuscation Prompt injection detection — two-tier defense (heuristics + fine-tuned ML model) against injected instructions in fetched content. See Prompt Injection Package supply-chain checks — registry existence, file reputation, and age analysis for npm/PyPI packages Plugin scanning — scans installed plugins for threats at session start AMSI integration — Windows Antimalware Scan Interface support (Windows + WSL via PowerShell interop; no-op on macOS and non

agentsaiclaude-codeclaude-code-plugincursor-aicursor-extensionopenclawsecurityvscode-extension

Quick Facts

Stars309
Forks31
LanguageTypeScript
CategoryCodex Skill
LicenseApache-2.0
Quality Score67.2323507244726/100
Open Issues9
Last Updated2026-09-16
Created2026-02-12
Platformsbrowser, claude-code, node, vscode
Est. Tokens~15k

Compatible Skills

These tools work well together with sage for enhanced workflows:

  • sage — semantic(0.94)+complementary+rare_topics+same_lang+similar_pop+shared_platform (79%)
  • BifrostMCP — semantic(0.28)+complementary+rare_topics+same_lang+similar_pop+shared_platform (59%)
  • verify — semantic(0.22)+complementary+same_lang+similar_pop+shared_platform (58%)
  • openclaw-a2a-gateway — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)
  • claw-empire — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)

sage alternative? Top 6 similar tools

Looking for a sage alternative? If you're comparing sage with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • sage by avast · ⭐ 119

    Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. P

  • Mysti by DeepMyst · ⭐ 1.1k

    AI coding dream team of agents for VS Code. Claude Code + openai Codex collaborate in brainstorm mode, debate

  • getspecstory by specstoryai · ⭐ 1.3k

    Install our local first extensions for your favorite AI IDE or Terminal Agent. Process your histories into reu

  • orchestkit by yonatangross · ⭐ 283

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • claude-code-safety-net by kenryu42 · ⭐ 1.3k

    A coding agent hook that acts as a safety net, catching destructive git and filesystem commands before they ex

  • mcp-scanner by cisco-ai-defense · ⭐ 1.1k

    Scan MCP servers for potential threats & security findings.

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is sage?

sage is Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.. It is categorized as a Codex Skill with 309 GitHub stars.

What programming language is sage written in?

sage is primarily written in TypeScript. It covers topics such as agents, ai, claude-code.

How do I install or use sage?

You can find installation instructions and usage details in the sage GitHub repository at github.com/gendigitalinc/sage. The project has 309 stars and 31 forks, indicating an active community.

What license does sage use?

sage is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to sage?

The top alternatives to sage on Agent Skills Hub include sage, Mysti, getspecstory. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools