by DeepMyst
AI coding dream team of agents for VS Code. Claude Code + openai Codex collaborate in brainstorm mode, debate solutions, and synthesize the best approach for your code.
# Add to your Claude Code skills
git clone https://github.com/DeepMyst/MystiLast scanned: 5/2/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@typescript-eslint/eslint-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@typescript-eslint/parser: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@typescript-eslint/type-utils: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@typescript-eslint/typescript-estree: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@typescript-eslint/utils: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "exceljs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "prismjs: PrismJS DOM Clobbering vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "terser-webpack-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior",
"severity": "low"
}
],
"status": "WARNING",
"scannedAt": "2026-05-02T06:08:06.882Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how Mysti compares with popular alternatives.
Mysti is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by DeepMyst. AI coding dream team of agents for VS Code. Claude Code + openai Codex collaborate in brainstorm mode, debate solutions, and synthesize the best approach for your code. It has 1,140 GitHub stars.
Mysti returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/DeepMyst/Mysti" and add it to your Claude Code skills directory (see the Installation section above).
Mysti is primarily written in TypeScript. It is open-source under DeepMyst on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh Mysti against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.

An open-source coding workspace that brings your agents together inside VS Code.
Ask Claude Code and Codex for independent opinions. Give a specialist a specific task. Hand completed work to another agent for review. Keep their responses, context, permissions, and progress in one conversation.
Mysti connects the coding tools you choose—CLI agents, local model servers, and the DeepMyst-powered Mysti coordinator. Use one agent when that's enough; bring in more when another perspective helps.
2.0 is a beta. This checkout prepares the 2.0.0 pre-release package. The Marketplace badge shows the currently published version. See release status and limitations before adopting it for important work.
16 provider adapters + the Mysti coordinator · Parallel opinions · Cross-agent handoffs · Connected tools · Proactive context
The recordings below use the shipped webviews with deterministic sample responses. They demonstrate interaction and presentation; they are not live provider runs or performance benchmarks. Capture details and video downloads.
An answer is a starting point. On answers with a usage or session receipt, click Second opinion, choose another configured agent, and Mysti sends it the original question. Compare separately attributed answers in the same conversation; use Brainstorm when you want a discussion and synthesis.

@claude @codex What are your opinions on adding a cache to this API?
Explicit tags determine who does the work. Independent read-only assignments run concurrently within the configured limit. Each agent has its own live card and attributed answer—even if one of them is already your selected provider.

A failed participant stays visible. Mysti does not invent its answer or quietly ask the other agent to impersonate it.
@claude Design a retry policy, then @codex review it for edge cases
Use then to make the next assignment depend on the previous result. Claude designs the policy; Codex receives that result to review. Progress cards show the current step and who runs next. A failed dependency blocks its dependent step.

Add roles such as @claude:critic or @codex:reviewer to make the perspective explicit. Independent advisory work can run in parallel; work that may edit a shared workspace runs serially. Assignment and workflow guide.
Choose from 16 registered provider adapters, plus the Mysti coordinator. Move between coding CLIs, local model servers, and API providers from the composer. Your draft stays in place, and model controls follow the selected provider's capabilities.

See all providers and setup requirements.
Choose the model, adjust effort, and toggle Ultracode where the provider supports it. The model menu and action menu share the same settings. Dictation adds text to your draft for review before you send.

Connect apps and MCP servers through DeepMyst's Composio and Smithery catalogs. Bring code, team discussions, email, and calendar context within reach of your agents through the tools you authorize. Browse and authorize in DeepMyst, then manage connections from Mysti.

The recording shows sample authorized connections, not a live OAuth flow. Catalog availability and tool permissions depend on the service and your account; local CLI access is opt-in for supported adapters. A connected app is not automatically a Proactive monitoring source.
Proactive brings selected local Git changes and DeepMyst-connected GitHub/Slack evidence into an inbox. The Before you start view helps you inspect relevant evidence for a responsibility, including source links and freshness information.

Cloud monitoring requires DeepMyst sign-in, a supported connection, and an explicitly configured responsibility. Coverage is bounded; evidence does not prove who owns a task. Proactive setup and limits.
Choose two configured agents and a discussion strategy. Quick collects independent analyses and synthesizes a response; Debate, Red Team, Perspectives and Delphi provide other ways to examine a proposal. Keep the individual reasoning visible alongside the synthesis.

| Feature | Why it matters | Explore |
|---|---|---|
| Brainstorm | Let two agents analyze, debate or challenge a proposal, then synthesize a response. | Discussion strategies |
| Canvas + Visual Test | Iterate on visual artifacts and inspect a running app alongside the code. | Visual workflows |
| Personas, skills and roles | Reuse project guidance and specialist perspectives instead of repeating instructions. | Team practices |
| Checkpoints + visible approvals | Inspect requested actions and recover supported local changes as you iterate. Checkpoints do not undo external actions. | Access and lifecycle |
| Dictation + context tools | Speak a draft, mention files, or attach diagnostics and Git context before sending. | Composer and context |
| When you need… | Use… | What happens |
|---|---|---|
| A direct answer or implementation | A selected provider, or @claude / @codex |
The named agent handles the request with your access settings. |
| Independent perspectives | @claude @codex with a question or review request |
Read-only assignments run concurrently; results remain separately attributed. |
| An ordered handoff | @claude Write the parser, then @codex review it |
The reviewer receives the completed result as reference material. A failed dependency blocks the handoff. |
| A defined perspective | @claude:critic @codex:reviewer |
Catalog roles shape each response and restrict its access. |
| A structured discussion | Brainstorm | Choose a team and discussion strategy, then follow its rounds and synthesis. |
| A coordinating agent | Mysti | A DeepMyst-backed coordinator can answer, use configured tools, and delegate through permission gates. |
| Visual iteration | Canvas and Visual Test | Work with visual artifacts and inspect a running app; browser setup may be required. |
| Project-specific practices | Personas, skills, and roles | Reuse your team's guidance with explicit trust and access boundaries. |

Parallelism follows the work: independent advisory requests may overlap; writers share a workspace and run serially. Use then for an explicit dependency. Assignment syntax and troubleshooting.
@claude Explain the main entry point, then add @codex for a second opinion when both are configured.You only need one configured agent to begin. Provider subscriptions, API access, usage charges, and supported models vary. Getting started · [Provider setup