No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by gendigitalinc · Codex Skill · ★ 309
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is sage safe to install? View the security audit →
Sage Safety for Agents — Agent Detection & Response for AI coding assistants Sage is a lightweight security layer that protects AI agents from executing dangerous actions. It intercepts tool calls — shell commands, URL fetches, file writes — and checks them against multiple threat detection layers before they run. Note: Sage may appear under a different product name (e.g., Norton Sage, Avast Sage) depending on how it was installed. See Branding for details. Key Features URL reputation — cloud-based detection of malware, phishing, and scam URLs Local heuristics — 300+ YAML-based threat patterns for dangerous commands, suspicious URLs, credential exposure, and obfuscation Prompt injection detection — two-tier defense (heuristics + fine-tuned ML model) against injected instructions in fetched content. See Prompt Injection Package supply-chain checks — registry existence, file reputation, and age analysis for npm/PyPI packages Plugin scanning — scans installed plugins for threats at session start AMSI integration — Windows Antimalware Scan Interface support (Windows + WSL via PowerShell interop; no-op on macOS and non
| Stars | 309 |
| Forks | 31 |
| Language | TypeScript |
| Category | Codex Skill |
| License | Apache-2.0 |
| Quality Score | 67.2323507244726/100 |
| Open Issues | 9 |
| Last Updated | 2026-09-16 |
| Created | 2026-02-12 |
| Platforms | browser, claude-code, node, vscode |
| Est. Tokens | ~15k |
These tools work well together with sage for enhanced workflows:
Looking for a sage alternative? If you're comparing sage with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. P
AI coding dream team of agents for VS Code. Claude Code + openai Codex collaborate in brainstorm mode, debate
Install our local first extensions for your favorite AI IDE or Terminal Agent. Process your histories into reu
The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl
A coding agent hook that acts as a safety net, catching destructive git and filesystem commands before they ex
Scan MCP servers for potential threats & security findings.
Explore other popular codex skill tools:
sage is Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.. It is categorized as a Codex Skill with 309 GitHub stars.
sage is primarily written in TypeScript. It covers topics such as agents, ai, claude-code.
You can find installation instructions and usage details in the sage GitHub repository at github.com/gendigitalinc/sage. The project has 309 stars and 31 forks, indicating an active community.
sage is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to sage on Agent Skills Hub include sage, Mysti, getspecstory. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: