claude-toolbox — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by serpro69 · MCP Server · ★ 149

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is claude-toolbox safe to install? View the security audit →

About claude-toolbox

claude-toolbox is a collection of "tools" for all your agentic workflows — pre-configured MCP servers, skills, sub-agents, commands, hooks, statuslines with themes, and more - everything you need for AI-powered development workflows, used and battle-tested daily on many of my own projects. Supported providers: Claude Code · Codex [Read the full documentation

agent-skillsagentsclaudeclaude-codeclaude-code-pluginclaude-configclaude-pluginclaude-skillsclaude-startergo

Quick Facts

Stars149
Forks31
LanguageShell
CategoryMCP Server
Quality Score66.4815083123889/100
Open Issues13
Last Updated2026-09-21
Created2025-10-17
Platformsclaude-code, cli, mcp
Est. Tokens~12k

Compatible Skills

These tools work well together with claude-toolbox for enhanced workflows:

  • the-startup — semantic(0.46)+complementary+rare_topics+same_lang+similar_pop+shared_platform (66%)
  • ai-marketing-claude-code-skills — semantic(0.27)+complementary+same_lang+similar_pop+shared_platform (59%)
  • skills — semantic(0.36)+complementary+same_lang+similar_pop+shared_platform (58%)
  • claude-code-java — semantic(0.23)+complementary+rare_topics+same_lang+similar_pop+shared_platform (58%)

claude-toolbox alternative? Top 6 similar tools

Looking for a claude-toolbox alternative? If you're comparing claude-toolbox with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • developer-kit by giuseppe-trisciuoglio · ⭐ 343

    Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, comma

  • tutor-skills by RoundTable02 · ⭐ 400

    A Claude Code skill that turns PDFs, docs, and codebases into Obsidian study vaults

  • claude-elixir-phoenix by oliver-kriska · ⭐ 556

    Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP

  • cursor-rules-java by jabrena · ⭐ 412

    An opinionated, AI-native development workflow for Java Enterprise — reusable Skills, Agents, Commands, and MC

  • orchestkit by yonatangross · ⭐ 283

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • symfony-ux-skills by smnandre · ⭐ 166

    Symfony UX skills for Claude, Gemini, Codex, ... Live Component, Twig Component, Turbo, Stimulus

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Shell Agent Tools

Frequently Asked Questions

What is claude-toolbox?

claude-toolbox is Minimal by design, explicitly multi-lang, production-ready and battle-tested collection of configs and plugins for your Claude Code agentic development workflows: mcp, configs, skills, agents and more. It is categorized as a MCP Server with 149 GitHub stars.

What programming language is claude-toolbox written in?

claude-toolbox is primarily written in Shell. It covers topics such as agent-skills, agents, claude.

How do I install or use claude-toolbox?

You can find installation instructions and usage details in the claude-toolbox GitHub repository at github.com/serpro69/claude-toolbox. The project has 149 stars and 31 forks, indicating an active community.

What are the best alternatives to claude-toolbox?

The top alternatives to claude-toolbox on Agent Skills Hub include developer-kit, tutor-skills, claude-elixir-phoenix. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools