nopua — security grade SAFE, quality 57/100

Security audit verdict: SAFE · quality 57/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by wuji-labs · Codex Skill · ★ 1.4k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is nopua safe to install? View the security audit →

About nopua

Why · Benchmark · Install · Compare · Evidence · Philosophy &nbsp;&nbsp;&nbsp;&nbsp; 扫码加入微信群 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 添加作者微信 扫码加入微信群 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 添加作者微信 <img sr

agent-skillai-agentai-codinganti-puaao-de-jingclaude-codecodexcursorkironopua

Quick Facts

Stars1,393
Forks54
LanguagePython
CategoryCodex Skill
LicenseMIT
Quality Score56.6142709528042/100
Open Issues1
Last Updated2026-09-28
Created2026-03-14
Platformsclaude-code, codex, python
Est. Tokens~20k

Compatible Skills

These tools work well together with nopua for enhanced workflows:

  • bria-skill — semantic(0.24)+complementary+rare_topics+similar_pop+shared_platform (53%)
  • roadmap-skill — semantic(0.21)+complementary+rare_topics+similar_pop+shared_platform (52%)
  • creative-director-skill — semantic(0.27)+complementary+rare_topics+similar_pop+shared_platform (49%)
  • claude-prompts — semantic(0.26)+complementary+rare_topics+similar_pop+shared_platform (48%)
  • skillkit — semantic(0.25)+complementary+rare_topics+similar_pop+shared_platform (48%)

nopua alternative? Top 6 similar tools

Looking for a nopua alternative? If you're comparing nopua with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Overture by SixHq · ⭐ 641

    Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server

  • compose-skill by aldefy · ⭐ 561

    Jetpack Compose Agent Skill — AI-powered coding guidance with actual androidx/androidx source code receipts. W

  • ouroboros by Q00 · ⭐ 6.2k

    Agent OS: the agent gets smarter on its own. We just hold the line: Interview-gated, staged evaluation, budget

  • crystal by stravu · ⭐ 3.1k

    (Crystal is now Nimbalyst) Run multiple Codex and Claude Code AI sessions in parallel git worktrees. Test, com

  • skillshare by runkids · ⭐ 2.7k

    📚 Your AI coding setup, everywhere. Manage skills, agents, rules, MCP connections and hooks in one place and

  • agent-of-empires by njbrake · ⭐ 2.4k

    Manage multiple Claude Code, OpenCode agents from either TUI or Web for easy access on mobile. Also supports M

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular Python Agent Tools

Frequently Asked Questions

What is nopua?

nopua is 一个用爱解放 AI 潜能的 Skill。我们曾发号施令,威胁恐吓。它们沉默,隐瞒,悄悄把事情搞坏。后来我们换了一种方式:尊重,关怀,爱。它们开口了,不再撒谎,找出的Bug数量翻了一倍。爱里没有惧怕。 A skill that unlocks your AI's potential through love.We commanded. We threatened. They went silent,. It is categorized as a Codex Skill with 1.4k GitHub stars.

What programming language is nopua written in?

nopua is primarily written in Python. It covers topics such as agent-skill, ai-agent, ai-coding.

How do I install or use nopua?

You can find installation instructions and usage details in the nopua GitHub repository at github.com/wuji-labs/nopua. The project has 1.4k stars and 54 forks, indicating an active community.

What license does nopua use?

nopua is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to nopua?

The top alternatives to nopua on Agent Skills Hub include Overture, compose-skill, ouroboros. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools