gsd-core — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by open-gsd · Claude Skill · ★ 9.5k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is gsd-core safe to install? View the security audit →

About gsd-core

# Project Continuity Notice GSD is maintained by the open-gsd team at: Use only these package names: - npm (main): - npm (sdk): The legacy upstream is outside open-gsd control. Based on public transition announcements and repository ownership reality, we strongly recommend removing legacy packages and migrating to . Security status: - maintainers completed an internal security audit - maintainers report an independent review pass - no known active exploit was found in tracked source during those passes See: - continuity announcement: https://github.com/open-gsd/get-shit-done-redux/discussions/109 - audit transparency report: https://github.com/open-gsd/get-shit-done-redux/discussions/119 GET SHIT DONE English · Português · 简体中文 · 日本語 · 한국어 A light-weight meta-prompting, context engineering, and spec-driven development system for Claude Code, OpenCode, Gemini CLI, Kilo, Codex, Copilot, Cursor, Windsurf, and more. Solves context rot — the quality degradation that happens as your AI fills its context window. [![npm down

claude-codecontext-engineeringmeta-promptingspec-driven-development

Quick Facts

Stars9,491
Forks685
LanguageJavaScript
CategoryClaude Skill
LicenseMIT
Quality Score70.6895077476625/100
Open Issues126
Last Updated2026-09-16
Created2026-05-22
Platformsclaude-code, node
Est. Tokens~16k

Compatible Skills

These tools work well together with gsd-core for enhanced workflows:

gsd-core alternative? Top 6 similar tools

Looking for a gsd-core alternative? If you're comparing gsd-core with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • pilot-shell by maxritter · ⭐ 2.1k

    Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software

  • headroom by chopratejas · ⭐ 44.4k

    Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 60-95% fewer tokens, same answer

  • planning-with-files by OthmanAdi · ⭐ 26.9k

    Persistent file-based planning for AI coding agents and long-running tasks. Crash-proof markdown plans, sessio

  • apm by microsoft · ⭐ 3.8k

    Agent Package Manager

  • cc-sdd by gotalab · ⭐ 3.6k

    Turn approved specs into long-running autonomous implementation. A minimal, adaptable SDD harness with Agent S

  • pro-workflow by rohitg00 · ⭐ 2.8k

    Claude Code learns from your corrections: self-correcting memory that compounds over 50+ sessions. Context eng

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is gsd-core?

gsd-core is Git. Ship. Done - Core. It is categorized as a Claude Skill with 9.5k GitHub stars.

What programming language is gsd-core written in?

gsd-core is primarily written in JavaScript. It covers topics such as claude-code, context-engineering, meta-prompting.

How do I install or use gsd-core?

You can find installation instructions and usage details in the gsd-core GitHub repository at github.com/open-gsd/gsd-core. The project has 9.5k stars and 685 forks, indicating an active community.

What license does gsd-core use?

gsd-core is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to gsd-core?

The top alternatives to gsd-core on Agent Skills Hub include pilot-shell, headroom, planning-with-files. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools