crabbox — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by openclaw · Codex Skill · ★ 1.4k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is crabbox safe to install? View the security audit →

About crabbox

🦀 📦 Crabbox Warm a box, sync the diff, run the suite. Crabbox is a generic remote software testing and execution control plane. It is for maintainers, contributors, and automation that need to run repository commands somewhere other than the laptop in front of them: on managed cloud capacity, an existing SSH host, or a delegated sandbox provider. Crabbox keeps the local edit-save-run workflow, but moves the expensive or evidence-producing work onto a remote runner. Behind that one command, Crabbox leases or selects a runner, syncs the current working tree, runs the command remotely, streams output back, records evidence, and releases or unclaims the target. The system is a Go CLI on your machine, an optional coordinator that owns provider credentials and lease state, and a managed or delegated runner. Run the coordinator on Cloudflare Workers with a Durable Object, or as a Node.js service backed by PostgreSQL. Who

agent-skillsherdr-pluginremote-test-runner

Quick Facts

Stars1,408
Forks183
LanguageGo
CategoryCodex Skill
LicenseMIT
Quality Score66.4264290736013/100
Open Issues37
Last Updated2026-09-20
Created2026-04-30
Platformsgo
Est. Tokens~24k

Compatible Skills

These tools work well together with crabbox for enhanced workflows:

  • basecamp-cli — semantic(0.18)+complementary+same_lang+similar_pop+shared_platform (56%)
  • hey-cli — semantic(0.18)+complementary+same_lang+shared_platform (46%)

crabbox alternative? Top 6 similar tools

Looking for a crabbox alternative? If you're comparing crabbox with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • deepchat by ThinkInAIXYZ · ⭐ 6.3k

    🐬DeepChat - A smart assistant that connects powerful AI to your personal world

  • awesome-agent-skills by heilcheng · ⭐ 6.2k

    Tutorials, Guides and Agent Skills Directories

  • Generative-Media-Skills by SamurAIGPT · ⭐ 4.3k

    Multi-modal Generative Media Skills for AI Agents (Claude Code, Cursor, Gemini CLI). High-quality image, video

  • terminal-browser by zenbu-labs · ⭐ 3.1k

    A browser inside your terminal

  • skills by microsoft · ⭐ 3.0k

    Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents

  • playwright-skill by lackeyjb · ⭐ 3.0k

    General-purpose Playwright automation for coding agents

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular Go Agent Tools

Frequently Asked Questions

What is crabbox?

crabbox is Crabbox: warm a box, sync the diff, run the suite.. It is categorized as a Codex Skill with 1.4k GitHub stars.

What programming language is crabbox written in?

crabbox is primarily written in Go. It covers topics such as agent-skills, herdr-plugin, remote-test-runner.

How do I install or use crabbox?

You can find installation instructions and usage details in the crabbox GitHub repository at github.com/openclaw/crabbox. The project has 1.4k stars and 183 forks, indicating an active community.

What license does crabbox use?

crabbox is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to crabbox?

The top alternatives to crabbox on Agent Skills Hub include deepchat, awesome-agent-skills, Generative-Media-Skills. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools