routa — security grade SAFE, quality 63/100

Security audit verdict: SAFE · quality 63/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by phodal · MCP Server · ★ 1.8k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is routa safe to install? View the security audit →

About routa

Routa Workspace-first multi-agent coordination platform for software delivery Demo • Architecture • How It Works • Why Routa • Quick Start • Docs • 中文 Routa is a workspace-first multi-agent coordination platform for software delivery. It keeps goals, tasks, sessions, traces, evidence, and review state visible on a board instead of burying them inside a single chat thread. Releases · Architecture · Feature Tree · [Quick Start](docs/quick-

Quick Facts

Stars1,775
Forks247
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score63.0817185571362/100
Open Issues25
Last Updated2026-08-04
Created2026-02-16
Platformsclaude-code, gemini, mcp, node
Est. Tokens~370k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is routa?

routa is Build your Agent Team - Multi-agent coordination platform — parses intent to structured Spec, routes via MCP/ACP/A2A protocols, supports Claude Code/OpenCode/Gemini with unified context. It is categorized as a MCP Server with 1.8k GitHub stars.

What programming language is routa written in?

routa is primarily written in TypeScript.

How do I install or use routa?

You can find installation instructions and usage details in the routa GitHub repository at github.com/phodal/routa. The project has 1.8k stars and 247 forks, indicating an active community.

What license does routa use?

routa is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools