No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by octelium · Codex Skill · ★ 75
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is cordium safe to install? View the security audit →
Cordium is a free and open source, self-hosted, identity-based sandbox platform built on Kubernetes and Octelium. It provides isolated, reproducible sandboxes for developers, AI agents, and automated workloads that are accessible through web terminals, SSH, CLI, and gRPC APIs. Cordium is a general-purpose platform that can be used for various use cases, including as a remote development environment for coding sessions (e.g. VSCode, Zed, etc.), sandboxes for AI agents and CI/CD workloads, and secretless secure remote access to infrastructure for developers and AI agents. What sets Cordium apart is how sandboxes access infrastructure (e.g. remote private resources behind NAT, publicly protected SaaS resources, etc.). Instead of injecting credentials into the sandbox, every sandbox runs with a dedicated Octelium identity. Authorized databases, SSH servers, HTTP APIs, Kubernetes clusters, and internal services are accessed through Octelium’s identity-aware, secretless access platform, so
| Stars | 75 |
| Forks | 8 |
| Language | Go |
| Category | Codex Skill |
| License | Apache-2.0 |
| Quality Score | 63.4858718732674/100 |
| Open Issues | 1 |
| Last Updated | 2026-09-13 |
| Created | 2026-03-01 |
| Platforms | claude-code, codex, go, k8s, vscode |
| Est. Tokens | ~20k |
These tools work well together with cordium for enhanced workflows:
Looking for a cordium alternative? If you're comparing cordium with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Kelos - The Kubernetes-native framework for orchestrating autonomous AI coding agents.
Claude Code running in sandbox. Packed as single portable executable with no dependency. Has better performanc
🛠️ The meta-harness for AI agents — scaffold your own focused, branded agent harness with its own npx CLI, MC
Self-hosted AI coding workspace to run and orchestrate Claude Code, Codex, Copilot, Cursor, Grok and OpenCode
Octo Terminal — The ultimate vibe coding terminal. AI-powered IDE with Claude, Codex, Ollama built-in. Termina
Postman MCP Server — connect AI agents (Claude Code, Cursor, VS Code Copilot, Gemini CLI) to your Postman coll
Explore other popular codex skill tools:
cordium is Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials.. It is categorized as a Codex Skill with 75 GitHub stars.
cordium is primarily written in Go. It covers topics such as ai, ai-agent, claude-code.
You can find installation instructions and usage details in the cordium GitHub repository at github.com/octelium/cordium. The project has 75 stars and 8 forks, indicating an active community.
cordium is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to cordium on Agent Skills Hub include kelos, ClaudeCage, agent-harness-generator. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: