dotfiles — security grade SAFE, quality 64/100

Security audit verdict: SAFE · quality 64/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by joshukraine · Agent Tool · ★ 425

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is dotfiles safe to install? View the security audit →

About dotfiles

My Dotfiles for macOS ![dotfiles screenshot][screenshot] 🤩 Highlights [Neovim][neovim] editor configured with [LazyVim][lazyvim]💤 [Starship][starship] prompt [Zsh][zsh] shell with [zsh-abbr][zsh-abbr] for abbreviations Flexible, terminal-based dev environment with [ghostty][ghostty] 👻 + [Tmux][tmux]! [Claude Code][claude-code] with custom skills, permission presets, and safety hooks Fast, idempotent setup with [GNU Stow][gnu-stow] New Mac bootstrap based on thoughtbot's [Laptop][laptop] Support for both Apple Silicon and Intel Macs [!NOTE] This project previously supported [Fish shell][fish] alongside Zsh. Fish support was removed in [PR #135][pr-135] (). If you were using the Fish configuration, you can reference that PR to see what changed or recover code for your own setup. ⚡️ Quick Setup Make sure macOS is up to date and you have installed the required software. Clone this repo. Read the setup script and check available options. Preview what the setup script will do (dry-run mode). Run the setup script.

ai-agentsasdfclaude-codedotfilesghosttykittylazyvimluamacosneovim

Quick Facts

Stars425
Forks49
LanguageShell
CategoryAgent Tool
LicenseMIT
Quality Score63.9614283224433/100
Open Issues7
Last Updated2026-09-21
Created2014-07-03
Platformsclaude-code, cli
Est. Tokens~17k

Compatible Skills

These tools work well together with dotfiles for enhanced workflows:

  • dotfiles — semantic(0.52)+complementary+rare_topics+same_lang+similar_pop+shared_platform (72%)
  • claudecode.nvim — semantic(0.49)+complementary+rare_topics+similar_pop+shared_platform (57%)
  • claude-forge — semantic(0.19)+complementary+rare_topics+same_lang+similar_pop+shared_platform (56%)

dotfiles alternative? Top 6 similar tools

Looking for a dotfiles alternative? If you're comparing dotfiles with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Calyx by yuuichieguchi · ⭐ 311

    A native macOS terminal app built on Ghostty for running and supervising coding agents

  • herminal by hoangperry · ⭐ 205

    Local-first native macOS terminal with Vietnamese IME support and coding-agent observability

  • hal-9000 by vinta · ⭐ 138

    Opinionated AI coding agent and dev environment automation for macOS

  • seance by no1msd · ⭐ 133

    A scrolling terminal multiplexer that tracks your AI coding agents.

  • factoryfloor by alltuner · ⭐ 111

    AI-powered macOS development workspace. Git worktrees, Claude Code sessions, and dev servers in a single nativ

  • dotfiles by denolfe · ⭐ 87

    :floppy_disk: dotfiles for macOS - includes zsh, claude, hyper key, global shortcuts, and tmux configurations.

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Shell Agent Tools

Frequently Asked Questions

What is dotfiles?

dotfiles is :round_pushpin: My dotfiles for macOS using Neovim, Zsh, and Ghostty + Tmux. It is categorized as a Agent Tool with 425 GitHub stars.

What programming language is dotfiles written in?

dotfiles is primarily written in Shell. It covers topics such as ai-agents, asdf, claude-code.

How do I install or use dotfiles?

You can find installation instructions and usage details in the dotfiles GitHub repository at github.com/joshukraine/dotfiles. The project has 425 stars and 49 forks, indicating an active community.

What license does dotfiles use?

dotfiles is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to dotfiles?

The top alternatives to dotfiles on Agent Skills Hub include Calyx, herminal, hal-9000. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools