comanda — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by kris-hansen · MCP Server · ★ 324

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is comanda safe to install? View the security audit →

About comanda

comanda Make coding agents earn their exit. Comanda is the terminal-native runtime for durable, self-improving agent work in a repository. Describe a workflow in English, inspect the generated program, run the coding agents you already use, and stop only when your own quality gates say the work is done. From an idea to a governed workflow Comanda starts with English, but ends with a YAML program you can inspect, version, and improve. Describe it. Inspect it. Run it. Improve it. Commit it. A loop does not finish because an agent says “DONE” Long-running work needs an observable exit criterion. Comanda's agentic loops persist stat

agentsaiai-agentsanthropicautomationclaudeclicodexcommand-linedevops

Quick Facts

Stars324
Forks26
LanguageGo
CategoryMCP Server
LicenseMIT
Quality Score70.5766375744793/100
Open Issues3
Last Updated2026-09-16
Created2024-10-23
Platformsclaude-code, cli, codex, gemini, go, mcp
Est. Tokens~17k

Compatible Skills

These tools work well together with comanda for enhanced workflows:

  • cc-fleet — semantic(0.25)+complementary+same_lang+similar_pop+shared_platform (59%)
  • Clipal — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (58%)
  • Clipal — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (58%)

comanda alternative? Top 6 similar tools

Looking for a comanda alternative? If you're comparing comanda with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agentsys by agent-sh · ⭐ 984

    AI writes code. This automates everything else · 24 plugins · 49 agents · 44 skills · for Claude Code, OpenCod

  • hcom by aannoo · ⭐ 490

    Let AI agents message, watch, and spawn each other across terminals. Claude Code, Codex, Antigravity CLI, Curs

  • gptree by travisvn · ⭐ 290

    A CLI tool to provide LLM context for coding projects by combining project files into a single text file (or c

  • claude-emporium by Vvkmnn · ⭐ 82

    🏛 [UNDER CONSTRUCTION] A (roman) claude plugin marketplace

  • cc-skills by terrylica · ⭐ 74

    Claude Code Skills Marketplace: plugins, skills for ADR-driven development, DevOps automation, ClickHouse mana

  • sre by SmythOS · ⭐ 1.3k

    The SmythOS Runtime Environment (SRE) is an open-source, cloud-native runtime for agentic AI. Secure, modular,

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is comanda?

comanda is The CLI-native orchestrator for AI agent workflows. Run Claude Code, Codex, Gemini CLI & Kimi Code from declarative YAML. Because the terminal is where real work happens.. It is categorized as a MCP Server with 324 GitHub stars.

What programming language is comanda written in?

comanda is primarily written in Go. It covers topics such as agents, ai, ai-agents.

How do I install or use comanda?

You can find installation instructions and usage details in the comanda GitHub repository at github.com/kris-hansen/comanda. The project has 324 stars and 26 forks, indicating an active community.

What license does comanda use?

comanda is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to comanda?

The top alternatives to comanda on Agent Skills Hub include agentsys, hcom, gptree. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools