Atlas / Skills / ikaijua / Awesome-AITools

Awesome-AIToolsSAFE

skills/ikaijua/awesome-aitools

Collection of AI-related utilities. Welcome to submit pull requests /收藏AI相关的实用工具,欢迎提交pull requests

Verdict
SAFE
Grade
B
Trust score
86 /100
Version
—
Hosts
7 documented
License
—
Stars
6,203
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Awesome AI Tools

English | 中文

This repo collects awesome AI tools. Welcome everyone to recommend more awesome AI tools together! Please use the following template as a reference for your recommendations. issue

💎 Sponsor

A huge thank you to our sponsors for their generous support!

Click to collapse

【Xuanshu API is a next-generation AI model routing gateway for enterprises, technical teams, and individual developers. It provides one-stop API access to world-class top models (Claude, GPT, Grok, etc.

Read from source at commit bff56c35d26eOBSERVED · 2026-09-30
02

Install

Commands as the repository documents them. They are shown, not run.

git clone https://github.com/msitarzewski/agency-agents.git
git clone https://github.com/msitarzewski/agency-agents.git
pip install browser-use
pip install browser-use
git clone https://github.com/block/buzz.git && cd buzz
git clone https://github.com/block/buzz.git && cd buzz
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
openclawmentioned
windsurfmentioned
04

Trust audit

SAFEgrade B · trust 86/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

MEDIUMInventory / provenance · skill.no_skill_md · CWE-1104
Why it matters. no SKILL.md at the audited path
Fix. a skill without its instruction file cannot be reviewed as one
LOWInventory / provenance · inv.hidden_file · CWE-1104
.lycheeignore
.lycheeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/deepseek-harness/README-CN.md:12
- **开箱即用的 CLI + Web UI。** 运行 `npx @deepseek-ai/dsh web` 即可在 `http://127.0.0.1:3080` 启动 Web UI;不需要单独的「headless」或「GUI」构建。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/deepseek-harness/README-CN.md:27
该命令会在 `http://127.0.0.1:3080` 启动 Web UI。`--host` / `--port` 等参数参见上游 Web UI 指南。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/deepseek-harness/README.md:12
- **CLI + Web UI out of the box.** Run `npx @deepseek-ai/dsh web` and the Web UI is served at `http://127.0.0.1:3080` by default. No separate "headless" vs "GUI" build.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/deepseek-harness/README.md:27
The command starts the Web UI, served at `http://127.0.0.1:3080` by default. See the Web UI guide in the upstream docs for the `--host` / `--port` flags.
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/oh-my-pi/README.md:56
# zsh — add to ~/.zshrc
Why it matters. instructs the agent to persist itself in the user's environment
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/oh-my-pi/README.md:59
# bash — add to ~/.bashrc
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/claude-code/README-CN.md:62
curl -fsSL https://claude.ai/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/claude-code/README.md:62
curl -fsSL https://claude.ai/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/grok-build/README-CN.md:53
curl -fsSL https://x.ai/cli/install.sh | bash   # macOS / Linux / Git Bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/grok-build/README.md:53
curl -fsSL https://x.ai/cli/install.sh | bash   # macOS / Linux / Git Bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/multica/README-CN.md:66
curl -fsSL https://raw.githubusercontent.com/multica-ai/multica/main/scripts/install.sh | bash -s -- --with-server
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:93
| Meta Muse | 🌱 Meta's personal AI agent that does tasks instead of chatting: books travel, fills forms, shops, and manages email/calendars, paying via one-time Stripe Link cards. Runs in an isolated 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:100
| DeepSeek-V4 | 🌟 DeepSeek's 4th generation flagship model, MIT-licensed and open-weight on Hugging Face. **V4-Pro 0813 GA** rolled out Aug 13, 2026; V4-Pro (1.6T MoE, 49B activated) and V4-Flash (284
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass, no_license.

Audited 2026-09-30 · audit v0.4.1 · source sha bff56c35d26efull audit observations/trust-audit/skill/ikaijua__awesome-aitools.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-30bff56c35d26eSAFEB86first audit
06

Questions

What does the Awesome-AITools skill do?

Collection of AI-related utilities. Welcome to submit pull requests /收藏AI相关的实用工具,欢迎提交pull requests

Is Awesome-AITools safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (86/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Awesome-AITools access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Awesome-AITools work with?

Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (bff56c35d26e), read on 2026-09-30. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement