golf — security grade SAFE, quality 74/100

Security audit verdict: SAFE · quality 74/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by golf-mcp · MCP Server · ★ 840

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is golf safe to install? View the security audit →

About golf

⛳ Golf Easiest framework for building MCP servers 📚 Documentation Overview Golf is a framework designed to streamline the creation of MCP server applications. It allows developers to define server's capabilities—tools, prompts, and resources—as simple Python files within a conventional directory structure. Golf then automatically discovers, parses, and compiles these components into a runnable MCP server, minimizing boilerplate and accelerating development. With Golf v0.2.0, you get enterprise-grade authentication (JWT, OAuth Server, API key, development tokens), built-in utilities for LLM interactions, and automatic telemetry integration. Focus on implementing your agent's logic while Golf handles authentication,

agent-runtimeaiai-agentai-agent-toolsai-agentsai-platformaiagentsauthauthenticationauthorization

Quick Facts

Stars840
Forks70
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score73.5311907720481/100
Open Issues2
Last Updated2026-09-09
Created2025-02-24
Platformsmcp, python
Est. Tokens~15k

Compatible Skills

These tools work well together with golf for enhanced workflows:

  • logfire — semantic(0.21)+complementary+rare_topics+same_lang+similar_pop+shared_platform (57%)
  • clawmetry — semantic(0.20)+complementary+rare_topics+same_lang+similar_pop+shared_platform (57%)
  • open-terminal — semantic(0.16)+complementary+same_lang+similar_pop+shared_platform (56%)
  • bedrock-agentcore-sdk-python — semantic(0.30)+complementary+same_lang+similar_pop+shared_platform (55%)

golf alternative? Top 6 similar tools

Looking for a golf alternative? If you're comparing golf with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • arcade-mcp by ArcadeAI · ⭐ 1.0k

    MCP Server Framework and Tool Development library for building custom capabilities into agents.

  • agents by inkeep · ⭐ 1.4k

    Create AI Agents in a No-Code Visual Builder or TypeScript SDK with full 2-way sync. For shipping AI assistant

  • openops by openops-cloud · ⭐ 1.1k

    The batteries-included, No-Code FinOps automation platform, with the AI you trust.

  • MakeMoneyWithAI by garylab · ⭐ 946

    A list of open-source AI projects you can use to generate income easily.

  • jadx-mcp-server by zinja-coder · ⭐ 764

    MCP server for JADX-AI Plugin

  • python-utcp by universal-tool-calling-protocol · ⭐ 650

    Official python implementation of UTCP. UTCP is an open standard that lets AI agents call any API directly, wi

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is golf?

golf is Production-Ready MCP Server Framework • Build, deploy & scale secure AI agent infrastructure • Includes Auth, Observability, Debugger, Telemetry & Runtime • Run real-world MCPs powering AI Agents. It is categorized as a MCP Server with 840 GitHub stars.

What programming language is golf written in?

golf is primarily written in Python. It covers topics such as agent-runtime, ai, ai-agent.

How do I install or use golf?

You can find installation instructions and usage details in the golf GitHub repository at github.com/golf-mcp/golf. The project has 840 stars and 70 forks, indicating an active community.

What license does golf use?

golf is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to golf?

The top alternatives to golf on Agent Skills Hub include arcade-mcp, agents, openops. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools