spec-kit-zh — security grade SAFE, quality 63/100

Security audit verdict: SAFE · quality 63/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by loulanyue · Codex Skill · ★ 337

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is spec-kit-zh safe to install? View the security audit →

About spec-kit-zh

🌱 Spec Kit ZH 更快地构建高质量软件。 一个开源工具包,让你专注于产品场景与可预期的结果,而不是从零开始凭感觉拼凑每一个实现细节。 目录 🤔 什么是规范驱动开发? ⚡ 快速开始 📽️ 视频概览 🚶 社区演练项目 🤖 支持的 AI 代理 🔧 specify-zh 命令参考 📚 核心理念 🌟 开发阶段 🎯 实验目标 [🔧 前置要求](#pre

ai-codingchineseclaude-codecodexcursordeveloper-toolslocalizationpythonspec-driven-developmentspec-kit

Quick Facts

Stars337
Forks26
LanguagePython
CategoryCodex Skill
LicenseMIT
Quality Score63.2165908660454/100
Open Issues23
Last Updated2026-09-01
Created2026-03-17
Platformsclaude-code, codex, python
Est. Tokens~21k

Compatible Skills

These tools work well together with spec-kit-zh for enhanced workflows:

  • spec-driven-workflow — semantic(0.47)+complementary+same_lang+similar_pop+shared_platform (66%)
  • spec_driven_develop — semantic(0.46)+complementary+same_lang+similar_pop+shared_platform (66%)
  • disciplined-agentic-engineering — semantic(0.42)+complementary+same_lang+similar_pop+shared_platform (65%)
  • eidos — semantic(0.41)+complementary+same_lang+similar_pop+shared_platform (64%)
  • Claude-Desktop-Chinese — semantic(0.25)+complementary+rare_topics+same_lang+similar_pop+shared_platform (63%)

spec-kit-zh alternative? Top 6 similar tools

Looking for a spec-kit-zh alternative? If you're comparing spec-kit-zh with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • quint-code by m0n0x41d · ⭐ 1.3k

    Engineering decisions engine that know when they're stale. Frame, compare, decide — with evidence decay and p

  • Aegis by GanyuanRan · ⭐ 1.2k

    Make AI coding agents architecture-aware: baseline-first, evidence-verified, drift-checked, and safe across lo

  • Overture by SixHq · ⭐ 630

    Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server

  • compose-skill by aldefy · ⭐ 561

    Jetpack Compose Agent Skill — AI-powered coding guidance with actual androidx/androidx source code receipts. W

  • sdd-pilot by attilaszasz · ⭐ 95

    Replace chaotic AI code generation with a disciplined, spec-driven workflow. SDD Pilot enforces structured dev

  • agtx by fynnfluegge · ⭐ 1.5k

    🏄🏼‍♂️ The blackboard for coding agents - agentic development environment for claude code, codex, cursor, ope

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular Python Agent Tools

Frequently Asked Questions

What is spec-kit-zh?

spec-kit-zh is Chinese-localized spec-driven development toolkit for Codex, Claude Code, Cursor, and other AI coding agents.. It is categorized as a Codex Skill with 337 GitHub stars.

What programming language is spec-kit-zh written in?

spec-kit-zh is primarily written in Python. It covers topics such as ai-coding, chinese, claude-code.

How do I install or use spec-kit-zh?

You can find installation instructions and usage details in the spec-kit-zh GitHub repository at github.com/loulanyue/spec-kit-zh. The project has 337 stars and 26 forks, indicating an active community.

What license does spec-kit-zh use?

spec-kit-zh is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to spec-kit-zh?

The top alternatives to spec-kit-zh on Agent Skills Hub include quint-code, Aegis, Overture. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools