
Research
TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.
@agents-inc/cli
Advanced tools
An agent composition framework for Claude Code.
Compose specialized Claude Code subagents from atomic skills. Choose your stack, customize your skills, and compile from the CLI.
npx @agents-inc/cli init
Choose from 16 pre-built stacks or start from scratch. Stacks pre-select skills and agents for common tech combinations.
| Stack | Technologies |
|---|---|
nextjs-fullstack | Next.js + React + Hono + Drizzle + Better Auth + Zustand |
nextjs-t3-stack | Next.js + tRPC + Prisma + NextAuth + Tailwind |
nextjs-supabase-fullstack | Next.js + Supabase + Drizzle + Better Auth |
nextjs-turborepo-fullstack | Next.js + Turborepo + pnpm Workspaces + Hono + Drizzle |
nextjs-ai-saas | Next.js + Vercel AI + Anthropic + Drizzle + Pinecone |
nextjs-saas-starter | Next.js + Better Auth + Stripe + Drizzle + Resend + PostHog |
react-old-school | React + Redux Toolkit + SCSS Modules + Vite + Vitest |
react-hono-fullstack | React + Vite + Hono + Drizzle + Better Auth |
remix-fullstack | Remix + Hono + Drizzle + Better Auth |
sveltekit-fullstack | SvelteKit + Hono + Drizzle + Better Auth |
solidjs-fullstack | SolidJS + Hono + Drizzle + Better Auth + Vitest |
astro-content-fullstack | Astro + Hono + Drizzle |
vue-modern-fullstack | Vue 3 + Pinia + Hono + Drizzle + Better Auth |
nuxt-fullstack | Nuxt + Hono + Drizzle + Better Auth |
angular-modern-fullstack | Angular + NgRx + Hono + Drizzle + Better Auth |
expo-mobile-fullstack | Expo + React Native + Zustand + React Query + Hono + Drizzle |
Add or remove skills from the interactive grid. Skills are organized by domain with framework-aware filtering.
Choose which subagents to compile. Each agent is composed from the skills you selected.
After init, use agentsinc edit to change selections and agentsinc compile to rebuild.
| Guide | Description |
|---|---|
| Install modes | Plugin vs local install, global vs project scope |
| Editing your config | Skill mappings, preloaded vs dynamic loading, and config structure |
| Customizing subagents | Eject and modify partials, templates, and skills |
| Writing custom skills and subagents | Author skills and subagents from scratch or iterate on existing ones |
| Importing third-party skills | Install skills from external repositories |
| Creating a marketplace | Build a personal or org-level marketplace with curated skills |
154 skills across 8 domains:
Web: React, Vue, Angular, Svelte, SolidJS, Next.js, Remix, Nuxt, SvelteKit, Astro, Qwik, Tailwind, SCSS Modules, Zustand, Redux, Pinia, Vitest, Playwright, Storybook, and more API: Hono, Express, Fastify, NestJS, Elysia, Drizzle, Prisma, PostgreSQL, MongoDB, Redis, Stripe, and more AI: Anthropic SDK, OpenAI SDK, Vercel AI SDK, LangChain, LlamaIndex, Pinecone, ChromaDB, and more Mobile: React Native, Expo CLI: Commander, oclif + Ink Infra: Docker, GitHub Actions, Cloudflare Workers Shared: Turborepo, ESLint + Prettier, Code Reviewing, Auth Security, and more Meta: Research Methodology, CLI Reviewing
Browse the full catalog on the Plugin Marketplace.
| Category | Subagents |
|---|---|
| Developers | web-developer api-developer cli-developer web-architecture |
| Reviewers | web-reviewer api-reviewer cli-reviewer |
| Testers | web-tester cli-tester |
| Researchers | web-researcher api-researcher |
| Planning | web-pm |
| Pattern Analysis | pattern-scout web-pattern-critique |
| Documentation | codex-keeper |
| Meta | skill-summoner agent-summoner convention-keeper |
Each subagent is composed from modular partials (role, workflow, output format) plus its assigned skills. Everything is ejectable.
| Command | Description |
|---|---|
init | Interactive setup wizard: pick a stack, customize skills, compile subagents |
edit | Modify skill selection via the interactive wizard |
compile | Recompile subagents after changes |
update | Pull latest skills from source |
search | Search skills across all sources |
| Command | Description |
|---|---|
eject <type> | Export for customization (agent-partials, templates, skills, all) |
new skill | Scaffold a custom skill |
new agent | Scaffold a custom agent |
new marketplace | Scaffold a new skill marketplace |
import skill | Import a skill from an external GitHub repository |
| Command | Description |
|---|---|
build marketplace | Generate marketplace.json from source skills |
build plugins | Build skill and agent plugins for distribution |
build stack | Build a stack as a single plugin |
| Command | Description |
|---|---|
config | Show config overview |
config show | Display all resolved config values |
config path | Show config file paths |
| Command | Description |
|---|---|
doctor | Diagnose setup issues |
diff | Show changes between local and source skills |
list | List installed skills |
outdated | Check for skill updates |
validate | Validate config and skill structure |
info | Show project configuration details |
uninstall | Remove Agents Inc from your project |
Run agentsinc --help for full usage.
MIT
FAQs
CLI for managing Agents Inc. skills, stacks, and agents for Claude Code
The npm package @agents-inc/cli receives a total of 705 weekly downloads. As such, @agents-inc/cli popularity was classified as not popular.
We found that @agents-inc/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.

Security News
/Research
Widespread GitHub phishing campaign uses fake Visual Studio Code security alerts in Discussions to trick developers into visiting malicious website.