No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by professorpalmer · Codex Skill · ★ 444
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is Puppetmaster safe to install? View the security audit →
Puppetmaster Turn Cursor, Claude Code (Anthropic or AWS Bedrock), the OpenAI API, or the Codex CLI into an orchestrator that routes every task to the cheapest model that can handle it, runs workers as independent processes, and stores their output as typed SQLite artifacts so follow-ups cost zero tokens. 💸 Reproduce the live A/B in $0.01 of spend — . Pinned cost \$0.0132; Puppetmaster routed
| Stars | 444 |
| Forks | 38 |
| Language | Python |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 65.567896576187/100 |
| Last Updated | 2026-09-19 |
| Created | 2026-05-06 |
| Platforms | claude-code, codex, python |
| Est. Tokens | ~17k |
These tools work well together with Puppetmaster for enhanced workflows:
Looking for a Puppetmaster alternative? If you're comparing Puppetmaster with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Define task-specific AI sub-agents in Markdown for any MCP-compatible tool.
Web, Desktop & Mobile client and orchestrator for Codex, Claude Code, OpenCode, Pi, Cursor, Grok, Antigravity,
The SmythOS Runtime Environment (SRE) is an open-source, cloud-native runtime for agentic AI. Secure, modular,
Battle-tested Claude Code, OpenAI Codex, Cursor configs, plugins, hooks and agents with Kimi, MiniMax and GLM
Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server
Safe runtime for autonomous on-chain AI agents: isolated sandboxes, Library skills, encrypted secrets.
Explore other popular codex skill tools:
Puppetmaster is Provider-neutral control plane for durable-state agent swarms: subprocess workers, leases, artifacts, memory, and deterministic stitching.. It is categorized as a Codex Skill with 444 GitHub stars.
Puppetmaster is primarily written in Python. It covers topics such as agent-swarms, agents, ai-agents.
You can find installation instructions and usage details in the Puppetmaster GitHub repository at github.com/professorpalmer/Puppetmaster. The project has 444 stars and 38 forks, indicating an active community.
Puppetmaster is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to Puppetmaster on Agent Skills Hub include sub-agents-mcp, happier, sre. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: