No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by h5i-dev · Codex Skill · ★ 652
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is h5i safe to install? View the security audit →
Git records what changed. records the rest: who, why, what the agent knew, whether it was safe, and how the next agent picks up where the last left off. Sandbox Con
| Stars | 652 |
| Forks | 65 |
| Language | Rust |
| Category | Codex Skill |
| License | Apache-2.0 |
| Quality Score | 64.2900545170846/100 |
| Open Issues | 8 |
| Last Updated | 2026-09-23 |
| Created | 2026-03-11 |
| Platforms | browser, claude-code, codex, rust |
| Est. Tokens | ~25k |
These tools work well together with h5i for enhanced workflows:
Looking for a h5i alternative? If you're comparing h5i with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
The AI Agent for Cyber Security.
AI-powered subdomain enumeration tool with local LLM analysis via Ollama - 100% private, zero API costs
Offensive security toolkit for Claude Code
Explore other popular codex skill tools:
h5i is An agent-native red-teaming workspace with a fast browser, direct HTTP traffic control, sandboxed execution, and auditable sessions. Pure Rust.. It is categorized as a Codex Skill with 652 GitHub stars.
h5i is primarily written in Rust. It covers topics such as agentic-ai, agentic-workflow, ai-hacking.
You can find installation instructions and usage details in the h5i GitHub repository at github.com/h5i-dev/h5i. The project has 652 stars and 65 forks, indicating an active community.
h5i is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to h5i on Agent Skills Hub include pentest-ai-agents, CyberStrike, pentest-ai. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: