cli — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by supermodeltools · MCP Server · ★ 91

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is cli safe to install? View the security audit →

About cli

Supermodel CLI Save 40%+ on agent token costs with code graphs. Supermodel maps every file, function, and call relationship in your repo and writes a file next to each source file. Your agent reads them automatically via grep and cat. No prompt changes. No extra context windows. No new tools to learn. 📖 Full CLI docs: docs.supermodeltools.com/cli/install Linux / Mac npm (cross-platform) How it works 1. Map your codebase Uploads your repo to the Supermodel API, builds a full call graph, and writes shard files next to every source file. Stays running to keep files updated as you code. 2. Your agent reads the graph automatically files are plain text. Any agent that can read files — Claude Code, Cursor, Copilot, Windsurf — picks them up automatically through its native search & file reading tools. No configuration needed on the agent side. 3. Ask anything Your agent now has full visibility into your call graph, imports, domains, and blast radius — for every file in the repo, not just the ones open in the editor. Works with any AI agent files are plain text read via grep and cat. There is no agent-specific integration required. Run ; install the hook f

aiai-codingcall-graphclaude-codeclicode-analysisdead-codedependency-graphdeveloper-toolsmcp

Quick Facts

Stars91
Forks12
LanguageGo
CategoryMCP Server
LicenseMIT
Quality Score73.2624651519341/100
Open Issues11
Last Updated2026-07-20
Created2026-03-31
Platformsclaude-code, cli, go, mcp
Est. Tokens~72k

cli alternative? Top 6 similar tools

Looking for a cli alternative? If you're comparing cli with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • stacklit by glincker · ⭐ 101

    One command gives AI agents instant codebase context. ~250 tokens replaces 50,000+ tokens of exploration. Auto

  • fossil-mcp by yfedoseev · ⭐ 65

    The code quality toolkit for the agentic AI era. Find dead code, clones, and scaffolding across 15 languages.

  • tree-sitter-analyzer by aimasteracc · ⭐ 50

    Cross-language-safe code-intelligence MCP for AI agents: 13 languages, family-gated call graph, blast radius,

  • claude-code-open by kill136 · ⭐ 158

    Open source AI coding platform with Web IDE, multi-agent system, 37+ tools, MCP protocol. MIT licensed.

  • depwire by depwire · ⭐ 61

    The missing context layer for AI-assisted refactoring

  • excalidraw-architect-mcp by BV-Venky · ⭐ 146

    Turn your architecture into a living, queryable knowledge graph - and render it as beautiful auto-laid-out Exc

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is cli?

cli is Save 40%+ on agent token costs with code graphs: call graphs, dependency graphs, dead code detection, and blast radius analysis.. It is categorized as a MCP Server with 91 GitHub stars.

What programming language is cli written in?

cli is primarily written in Go. It covers topics such as ai, ai-coding, call-graph.

How do I install or use cli?

You can find installation instructions and usage details in the cli GitHub repository at github.com/supermodeltools/cli. The project has 91 stars and 12 forks, indicating an active community.

What license does cli use?

cli is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to cli?

The top alternatives to cli on Agent Skills Hub include stacklit, fossil-mcp, tree-sitter-analyzer. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools