No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by rentruewang · LLM Plugin · ★ 289
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is bocoel safe to install? View the security audit →
🫙 Archive This has topped the show HN front page link. This was born as a research project, and I think I have achieved most of what I set out to create. So today (2025/09/14) I'm archiving this repository. Nowadays I'm mainly working on , a deep learning algorithm compiler! Check it out. ☂️ BoCoEL Bayesian Optimization as a Coverage Tool for Evaluating Large Language Models 
🦙 Integrating LLMs into structured NLP pipelines
A set of tools that gives agents powerful capabilities.
ToRA is a series of Tool-integrated Reasoning LLM Agents designed to solve challenging mathematical reasoning
Explore other popular llm plugin tools:
bocoel is Bayesian Optimization as a Coverage Tool for Evaluating LLMs. Accurate evaluation (benchmarking) that's 10 times faster with just a few lines of modular code.. It is categorized as a LLM Plugin with 289 GitHub stars.
bocoel is primarily written in Python. It covers topics such as bayesian-optimization, benchmarking, evaluation.
You can find installation instructions and usage details in the bocoel GitHub repository at github.com/rentruewang/bocoel. The project has 289 stars and 16 forks, indicating an active community.
bocoel is released under the BSD-3-Clause license, making it free to use and modify according to the license terms.
The top alternatives to bocoel on Agent Skills Hub include Awesome-LLM-Eval, create-llm, Hegelion. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: