🌊 Lagune is your security copilot as you build, your Blue Team when you audit, whether you're a developer or not.
Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + OpenAI Agents + Browser agents
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add wellwelwel/lagune
Maintenance
fresh
3d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
72
75/100 quality · 73/100 trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewInstall readiness, security metadata, maintenance, and adoption risk.
Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
72 GitHub stars
Repo activity
72 stars, 1 forks
Maintenance
3d since push
License
MIT
Install
npx skills add wellwelwel/lagune
Install safety
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Do not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Install targets
Copy the registry command or an agent-specific install prompt for Codex, Claude Code, and Cursor.
Use the registry command when your workflow supports the OpenAgentSkill installer.
$ npx skills add wellwelwel/laguneAgent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Resolve JSON
/api/agent/resolve?task=Use%20Lagune%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Lagune%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/wellwelwel-lagune/install
Agent should check
Copy prompt
Task: Use Lagune in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Lagune%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/wellwelwel-lagune/install
Install command: npx skills add wellwelwel/lagune
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/wellwelwel-lagune/install
LLM text format
/api/skills/wellwelwel-lagune/install?format=text
Find alternatives
/api/skills/search?q=Lagune&limit=3
Agent prompt
Use Lagune for this task. Review https://www.openagentskill.com/api/skills/wellwelwel-lagune/install, then install with: npx skills add wellwelwel/laguneRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/wellwelwel-lagune
LLM text
/api/registry/manifest/wellwelwel-lagune?format=text
Install alias
/api/registry/install/wellwelwel-lagune
Recommend
/api/registry/recommend?task=Use%20Lagune%20in%20an%20agent%20workflow&limit=3
Agent fit
Coding agents
Use-case tags
Platforms
TypeScript, Claude Code, OpenAI Agents, Browser agents
Audit report
Review install readiness, maintenance, trust, quality, and metadata warnings before adding this skill to an agent workflow.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Coding agents
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
Review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
CHECK72 GitHub stars
Stars/forks activity
CHECK72 stars, 1 forks; issue activity unavailable in current metadata
Recent maintenance
PASS3d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Search private knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Stack fit
Inspect, patch, and verify code
A stack for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
A stack for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Ingest, retrieve, and cite
A stack for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills in this category, ranked with the same readiness and quality signals.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
<img src="./website/static/img/banner.png" />
# 🌊 [Lagune AI](https://lagune.ai)
[](https://www.npmjs.com/package/lagune) [](https://lagune.ai/docs) [](https://lagune.ai/docs/supported-agents)
**Lagune** helps your AI agent make a project more secure. You point it at your code, and the agent figures out what your system actually does, then guides you through the security work that matters for it.
- **Lagune** works with projects in **any programming language** and supports [**72 agents**](https://lagune.ai/docs/supported-agents) ✨
---
Love **Lagune**? [**Give us a ⭐ on GitHub**](https://github.com/wellwelwel/lagune)!
---
## Table of Contents
- 🌊 [**Get Started**](#get-started) - 📦 [**Dashboard**](#dashboard) | [**CLI**](#cli) - 💬 [**Slash Commands**](#slash-commands) - 💽 [**Requirements**](#requirements) - 🔐 [**Security**](#security) - 🖖 [**Acknowledgements**](#acknowledgements) - 🧑⚖️ [**License**](#license)
---
## Get Started
**Lagune** adapts to your environment, whether it is a new project or an existing one.
> [!TIP] > > No API keys are needed, it runs directly through your own agent [(**Claude**, **Codex**, and more)](https://lagune.ai/docs/supported-agents).
---
### Dashboard
For an interactive live view, follow-up, and maintenance, run:
```bash npx -y lagune@latest ```
It serves a dashboard and opens it in a random port:
- [x] **Live Reload** - [x] **Private** and **Local** - [x] **Install**, **Pull**, **Update**, and **Manage** all **Lagune** features directly from your browser - [x] No `node_modules` or `package.json` is needed 📦
> <img width="260" src="./website/static/img/dashboard/01.png" /> > <img width="260" src="./website/static
Frameworks & Tools
Decision snapshot
recent repository activity
Audit snapshot
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the audit before production use.
Growth loop
Scenario-led draft for Lagune, ready for a manual X post.
Most coding agents don't fail from lack of model power. They fail when repo context disappears. Lagune gives coding agents a repeatable way to plan, patch, review, or ship. 72 stars https://www.openagentskill.com/skills/wellwelwel-lagune?ref=x #AIAgents
Listing + install path for Lagune: https://www.openagentskill.com/skills/wellwelwel-lagune?ref=x Install: npx skills add wellwelwel/lagune
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This community indexed listing is attributed to wellwelwel but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/wellwelwel-lagune)
[](https://www.openagentskill.com/skills/wellwelwel-lagune)
[](https://www.openagentskill.com/skills/wellwelwel-lagune/audit)
[](https://www.openagentskill.com/skills/wellwelwel-lagune)wellwelwel
@wellwelwel
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K stars · 0 installsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K stars · 0 installsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K stars · 0 installsWazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
15.9K stars · 0 installs