vibekit — security grade SAFE, quality 61/100

Security audit verdict: SAFE · quality 61/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by superagent-ai · Codex Skill · ★ 1.9k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is vibekit safe to install? View the security audit →

About vibekit

VibeKit is the safety layer for your coding agent 🖖 Run Claude Code, Gemini, Codex — or any coding agent — in a clean, isolated sandbox with sensitive data redaction and observability baked in. Website • Docs • Discord 🚀 Quick Start Install the VibeKit CLI globally: Run claude code with enhanced security and tracking ⚡️ Key Features 🐳 Local sandbox - Runs agent output in isolated Docker containers — zero risk to your local setup 🔒 Built-in redaction - Auto-removes secrets, api keys, and other sensitive data completions 📊 Observability - Complete visibility into agent operations with real-time logs, traces, and metrics 🌐 Universal agent support - Works with Claude Code, Gemini CLI, Grok CLI, Codex CLI, OpenCode, and more 💻 Works offline & locally - No cloud dependencies or internet required — works entirely on your machine 📦 Related Packages Looking to integrate VibeKit into your application? Check out these packages: 📚 VibeKit SDK Run coding agents in secure sandboxes with full control and monitoring. Perfect for building applications that need to execute AI-generated co

agentaiclaude-codecodexgemini-clivibe-coding

Quick Facts

Stars1,857
Forks248
LanguageTypeScript
CategoryCodex Skill
LicenseMIT
Quality Score60.757722158849/100
Open Issues37
Last Updated2026-01-13
Created2025-05-14
Platformsclaude-code, cli, codex, gemini, node
Est. Tokens~2187k

vibekit alternative? Top 6 similar tools

Looking for a vibekit alternative? If you're comparing vibekit with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agentsys by agent-sh · ⭐ 984

    AI writes code. This automates everything else · 24 plugins · 49 agents · 44 skills · for Claude Code, OpenCod

  • cursor-talk-to-figma-mcp by grab · ⭐ 7.0k

    TalkToFigma: MCP integration between AI Agent (Cursor, Claude Code, Codex) and Figma, allowing Agentic AI to c

  • openpencil by ZSeven-W · ⭐ 6.0k

    The world's first open-source AI-native vector design tool and the first to feature concurrent Agent Teams. De

  • tokscale by junhoyeo · ⭐ 5.5k

    🛰️ Track token usage across AI coding agents from your terminal. 🏅 Global leaderboard with trillions of toke

  • costrict by zgsm-ai · ⭐ 4.4k

    Costrict - strict AI coder for enterprises, quality first, including AI Agent, AI CodeReview, AI Completion.

  • crystal by stravu · ⭐ 3.1k

    (Crystal is now Nimbalyst) Run multiple Codex and Claude Code AI sessions in parallel git worktrees. Test, com

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is vibekit?

vibekit is Run Claude Code, Gemini, Codex — or any coding agent — in a clean, isolated sandbox with sensitive data redaction and observability baked in.. It is categorized as a Codex Skill with 1.9k GitHub stars.

What programming language is vibekit written in?

vibekit is primarily written in TypeScript. It covers topics such as agent, ai, claude-code.

How do I install or use vibekit?

You can find installation instructions and usage details in the vibekit GitHub repository at github.com/superagent-ai/vibekit. The project has 1.9k stars and 248 forks, indicating an active community.

What license does vibekit use?

vibekit is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to vibekit?

The top alternatives to vibekit on Agent Skills Hub include agentsys, cursor-talk-to-figma-mcp, openpencil. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools