opentaint — security grade SAFE, quality 65/100

Security audit verdict: SAFE · quality 65/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by seqra · Agent Tool · ★ 157

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is opentaint safe to install? View the security audit →

About opentaint

The open source taint analysis engine for the AI era Formal taint analysis for application security — finds what AST-pattern matchers miss, lets LLM agents enact vulnerabilities as rules, scales where neither can alone. English <a href="docs/transl

agentsai-securitycode-qualitycybersecurityhackingjavakotlinoffensive-securitysastsecurity

Quick Facts

Stars157
Forks12
LanguageKotlin
CategoryAgent Tool
LicenseApache-2.0
Quality Score65.3310654171395/100
Open Issues86
Last Updated2026-09-10
Created2025-09-30
Est. Tokens~18k

Compatible Skills

These tools work well together with opentaint for enhanced workflows:

  • spring-plugin — semantic(0.17)+complementary+rare_topics+same_lang+similar_pop (60%)
  • agent-audit — semantic(0.33)+complementary+rare_topics+similar_pop (56%)
  • code-pathfinder — semantic(0.45)+complementary+rare_topics+similar_pop (55%)
  • medusa — semantic(0.39)+complementary+rare_topics+similar_pop (53%)

opentaint alternative? Top 6 similar tools

Looking for a opentaint alternative? If you're comparing opentaint with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • fuzzforge_ai by FuzzingLabs · ⭐ 769

    AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulne

  • JoySafeter by jd-opensource · ⭐ 300

    🚀 JoySafeter: An enterprise AI Agent Platform—Not just chatting. building、running、testing, and tracing autono

  • agent-audit by HeadyZhang · ⭐ 211

    Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mappe

  • SecOpsAgentKit by AgentSecOps · ⭐ 184

    Security operations toolkit for AI coding agents. Give Claude Code 25+ skills to catch vulnerabilities, scan c

  • Awesome-AI-For-Security by AmanPriyanshu · ⭐ 145

    A curated list of tools, papers, and datasets for applying AI to cybersecurity tasks. This list primarily focu

  • mcp-for-security by cyproxio · ⭐ 628

    MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF,

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Kotlin Agent Tools

Frequently Asked Questions

What is opentaint?

opentaint is The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning token. It is categorized as a Agent Tool with 157 GitHub stars.

What programming language is opentaint written in?

opentaint is primarily written in Kotlin. It covers topics such as agents, ai-security, code-quality.

How do I install or use opentaint?

You can find installation instructions and usage details in the opentaint GitHub repository at github.com/seqra/opentaint. The project has 157 stars and 12 forks, indicating an active community.

What license does opentaint use?

opentaint is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to opentaint?

The top alternatives to opentaint on Agent Skills Hub include fuzzforge_ai, JoySafeter, agent-audit. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools