No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by wasintoh · Codex Skill · ★ 95
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is toh-framework safe to install? View the security audit →
"Type Once, Have it all!" — AI-Orchestration Driven Development Approve once. Walk away. Come back to a finished, verified app. Toh Framework installs an AI "build department" into your project: 14 slash commands, 8 specialist agents, and 23 skills — configured for Claude Code, Cursor, Antigravity, Codex, and ZCode in one install. You type one sentence (like ), approve once, and it plans, builds, tests, and fixes until the app is verified done. If you don't write code: you get one screen that asks for your idea in plain language and one "Go". No stack to choose, no config to fill in, no jargon to decode. The AI writes the plan as a checklist you can actually read, then works down it — building, runnin
| Stars | 95 |
| Forks | 19 |
| Language | JavaScript |
| Category | Codex Skill |
| License | MIT |
| Quality Score | 61.9247498846841/100 |
| Last Updated | 2026-09-02 |
| Created | 2025-11-27 |
| Platforms | claude-code, cli, codex, node |
| Est. Tokens | ~17k |
These tools work well together with toh-framework for enhanced workflows:
Looking for a toh-framework alternative? If you're comparing toh-framework with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Universal CLI for Agent Skills. Access 40,000+ skills from SkillsMP and sync them to Cursor, Claude Code, GitH
Local-first coordination for human and agent work: durable work, decisions, dispatches, evidence, and prompt-f
Define task-specific AI sub-agents in Markdown for any MCP-compatible tool.
Cross-LLM sub-agent orchestration as an Agent Skills. Route tasks to Codex, Claude Code, Grok, GLM, Kimi, Curs
Persistent Claude Code agents with scheduling, sessions, memory, and Telegram.
The open-source skill registry for AI coding agents. Create, manage, and distribute SKILL.md files across Open
Explore other popular codex skill tools:
toh-framework is Type one sentence, approve once, walk away — Toh Framework installs an AI build department (14 commands, 8 agents, 23 skills) into your project and keeps building, testing and fixing until it is verif. It is categorized as a Codex Skill with 95 GitHub stars.
toh-framework is primarily written in JavaScript. It covers topics such as agent-skills, agentic, agentic-workflow.
You can find installation instructions and usage details in the toh-framework GitHub repository at github.com/wasintoh/toh-framework. The project has 95 stars and 19 forks, indicating an active community.
toh-framework is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to toh-framework on Agent Skills Hub include agent-skills-cli, maestro, sub-agents-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: