ops0-cli — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by ops0-ai · MCP Server · ★ 75

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is ops0-cli safe to install? View the security audit →

About ops0-cli

ops0 CLI Policy, lint, vulnerability, and cost guardrails for AI coding agents. Sits in front of Claude Code, Codex and Gemini CLI. Every time the agent finishes writing IaC, the whole working directory gets validated, linted, policy-checked, security-scanned, and cost-estimated server-side. Failures come back as a failed tool call so the agent self-remediates. Destructive commands are blocked before they run. Quick start · What runs at end-of-turn · How agents trigger it · Monorepos · ops0-scan.md · Commands Why this exists When humans write infrastructure, policy gates fire on the PR. CI runs the scanner, someone gets paged, the PR sits in review for hours. When an agent writes infrastructure, that loop is broken. The agent will happily generate a public S3 bucket, an open security group, or an oversized EC2 fleet. By the time C

ai-agentsaudit-logclaude-codecli-toolcodexdevsecopsgemini-cligolang-cligovernanceiac

Quick Facts

Stars75
Forks3
LanguageGo
CategoryMCP Server
Quality Score65.9491249562043/100
Open Issues4
Last Updated2026-07-06
Created2025-06-10
Platformsclaude-code, cli, codex, gemini, go, mcp
Est. Tokens~19k

Compatible Skills

These tools work well together with ops0-cli for enhanced workflows:

  • ccx — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)

ops0-cli alternative? Top 6 similar tools

Looking for a ops0-cli alternative? If you're comparing ops0-cli with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agent-skills by jdrhyne · ⭐ 241

    A collection of AI agent skills for Clawdbot, Claude Code, Codex

  • agent-designer by appautomaton · ⭐ 130

    Portable SKILLs workspace for Claude Code, Codex, and Gemini — issue-driven workflows and cross-agent collabor

  • agentjail by LuD1161 · ⭐ 91

    Policy guardrails for coding agents (Claude Code, Codex, Cursor) — every tool call is checked locally, before

  • preloop by preloop · ⭐ 65

    The open-source AI agent control plane: MCP firewall, model gateway with budgets, human approvals, runtime obs

  • terrashark by LukasNiessen · ⭐ 323

    Terraform Skill for Claude Code and Codex. LLMs hallucinate a lot with Terraform - TerraShark fixes this. It e

  • deepcontext-mcp by Wildcard-Official · ⭐ 275

    DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is ops0-cli?

ops0-cli is Stop your AI agent from shipping insecure IaC. ops0 CLI sits between Claude Code, Codex or Gemini and your cloud, scanning every .tf the agent writes and blocking destroy commands before they run.. It is categorized as a MCP Server with 75 GitHub stars.

What programming language is ops0-cli written in?

ops0-cli is primarily written in Go. It covers topics such as ai-agents, audit-log, claude-code.

How do I install or use ops0-cli?

You can find installation instructions and usage details in the ops0-cli GitHub repository at github.com/ops0-ai/ops0-cli. The project has 75 stars and 3 forks, indicating an active community.

What are the best alternatives to ops0-cli?

The top alternatives to ops0-cli on Agent Skills Hub include agent-skills, agent-designer, agentjail. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools