costrict — security grade SAFE, quality 55/100

Security audit verdict: SAFE · quality 55/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by zgsm-ai · Agent Tool · ★ 4.4k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is costrict safe to install? View the security audit →

About costrict

CoStrict Strict AI Coder for Enterprises Free • Open Source • Private Deployment 简体中文 | English CoStrict is a free, open-source AI-powered coding assistant designed for enterprise-grade development. With support for private deployment, it's the optimal choice for organizations requiring secure, standardized AI development workflows. ✨ Core Capabilities Standardized AI c

agentagentic-aiaiaicodingclaude-codeclinecodingcostrictgemini-clijetbrains

Quick Facts

Stars4,430
Forks202
LanguageTypeScript
CategoryAgent Tool
LicenseApache-2.0
Quality Score54.8816383058042/100
Open Issues10
Last Updated2026-09-17
Created2025-04-10
Platformsclaude-code, cli, gemini, node
Est. Tokens~28547k

Compatible Skills

These tools work well together with costrict for enhanced workflows:

  • context-engineering-kit — semantic(0.25)+complementary+rare_topics+same_lang+similar_pop+shared_platform (58%)
  • ccmanager — semantic(0.21)+complementary+rare_topics+same_lang+similar_pop+shared_platform (57%)
  • pilot-shell — semantic(0.18)+complementary+same_lang+similar_pop+shared_platform (56%)
  • oh-my-claudecode — semantic(0.17)+complementary+same_lang+similar_pop+shared_platform (56%)
  • superset — semantic(0.17)+complementary+same_lang+similar_pop+shared_platform (56%)

costrict alternative? Top 6 similar tools

Looking for a costrict alternative? If you're comparing costrict with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • cc-skills-golang by samber · ⭐ 3.2k

    🧑‍🎨 A collection of Golang agentic skills that works

  • openpencil by ZSeven-W · ⭐ 6.0k

    The world's first open-source AI-native vector design tool and the first to feature concurrent Agent Teams. De

  • agentsys by agent-sh · ⭐ 984

    AI writes code. This automates everything else · 24 plugins · 49 agents · 44 skills · for Claude Code, OpenCod

  • cursor-talk-to-figma-mcp by grab · ⭐ 7.0k

    TalkToFigma: MCP integration between AI Agent (Cursor, Claude Code, Codex) and Figma, allowing Agentic AI to c

  • tokscale by junhoyeo · ⭐ 5.5k

    🛰️ Track token usage across AI coding agents from your terminal. 🏅 Global leaderboard with trillions of toke

  • axonhub by looplj · ⭐ 5.3k

    ⚡️ Open-source AI Gateway — Use any SDK to call 100+ LLMs. Built-in failover, load balancing, cost control & e

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is costrict?

costrict is Costrict - strict AI coder for enterprises, quality first, including AI Agent, AI CodeReview, AI Completion.. It is categorized as a Agent Tool with 4.4k GitHub stars.

What programming language is costrict written in?

costrict is primarily written in TypeScript. It covers topics such as agent, agentic-ai, ai.

How do I install or use costrict?

You can find installation instructions and usage details in the costrict GitHub repository at github.com/zgsm-ai/costrict. The project has 4.4k stars and 202 forks, indicating an active community.

What license does costrict use?

costrict is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to costrict?

The top alternatives to costrict on Agent Skills Hub include cc-skills-golang, openpencil, agentsys. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools