No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by jayminwest · Agent Tool · ★ 146
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is os-eco safe to install? View the security audit →
os-eco An integrated ecosystem of CLI tools for AI agent workflows. Each tool handles one concern — expertise, issues, prompts, runtime, sandbox, orchestration, or the autonomous loop — and
| Stars | 146 |
| Forks | 13 |
| Language | TypeScript |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 71.3179265537516/100 |
| Open Issues | 3 |
| Last Updated | 2026-08-02 |
| Created | 2026-02-24 |
| Platforms | node |
| Est. Tokens | ~50k |
Looking for a os-eco alternative? If you're comparing os-eco with other agent tool tools, these 3 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Lightweight registry to discover, install, and manage all public Claude plugins and agent skills for your favo
A Claude Code skill that turns PDFs, docs, and codebases into Obsidian study vaults
Power rename/refactor tool for CLI and agent use
Explore other popular agent tool tools:
os-eco is Meta-project for the AI agent tooling ecosystem — Mulch, Seeds, Canopy, and Overstory. It is categorized as a Agent Tool with 146 GitHub stars.
os-eco is primarily written in TypeScript.
You can find installation instructions and usage details in the os-eco GitHub repository at github.com/jayminwest/os-eco. The project has 146 stars and 13 forks, indicating an active community.
os-eco is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to os-eco on Agent Skills Hub include claude-plugins, tutor-skills, repren. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: