# Stop That Shit: a Hook and Skill Guard against AI agent scope creep

> Stop That Shit is a multi-platform Hook plus Skill Guard for Codex, Claude Code, OpenCode, Hermes Agent CLI and Pi. It denies covered tool calls that fall outside a task contract you write yourself, and it starts in a mode that only observes.

**lennney/stop-that-shit** — Stop That Shit（别再造史了）｜面向 Codex/GPT 场景的多平台 Hook + Skill Guard：拦截 AI coding agent 无需求的哈希、校验和与任务范围膨胀。 A multi-platform Hook + Skill Guard for AI coding agents in Codex/GPT workflows: stop unrequested hashes, checksums, and task-scope creep.

- Repository: https://github.com/lennney/stop-that-shit
- Website: https://take-a-deep-breath0.com/zh/stop-that-shit
- Stars: 2,437 · Forks: 52
- Language: JavaScript
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/lennney-stop-that-shit

## The failure this project is aimed at

You ask the agent to export one result file. It also writes a SHA-256 checksum that no later command reads. The README opens with exactly that example, and it is the clearest statement of the target: defensive work the agent added on its own, where each step looks reasonable in isolation but nothing in the current task consumes the output.

The README groups this into four directions under the acronym SHIT: scope creep, hashing and hypothetical hardening, intent violation (asked to review, it edits), and task thrashing (re-checking what was already checked). The project's framing is that it does not count lines of code and does not treat a smaller diff as automatically better. The only question it asks is whether a step was requested by the user or is genuinely required by the current code, data and acceptance criteria.

Who is this for? People running an AI coding agent inside one of the five host adapters and who have already tried the obvious fix of adding more prohibitions to AGENTS.md. The README describes that attempt directly: the rules get longer, and AGENTS.md itself starts to sprawl. Stop That Shit moves the parts that can be decided mechanically into a Skill plus an executable Guard.

## Stop Ladder, the Guard, and the red stamp

The architecture splits into two layers that share one task-boundary core across all five adapters. The Skill carries the Stop Ladder and the task-mode guidance. The Guard is the machine-executable part, and it only runs on Hook paths the host exposes.

You declare authorization with a mode such as review or change, then narrow it as needed with budgets for files, dependencies, hash and subagents. The Guard checks those explicit boundaries on covered Hook paths. When it decides an action is out of bounds, it returns a denial that the README renders as a red stamp containing STOP / INTENT, a permission deny, a reason code such as MODE_FORBIDS_MUTATION, the state (ARMED / review) and an event id.

Hashing gets priority treatment because a Hook can identify hash actions with comparatively high confidence in supported tool calls. The README states the criterion, credited to HERO: a digest must replace a more expensive operation, and the result must control the next step. Hashing every line and then still comparing line by line fails that test; using a digest to skip re-reading an unchanged large file passes it. The current version denies recognizable new hash operations by default, with hash=allow as the escape hatch when the user asked for it or the repository's code and release process prove it necessary. The README is candid that the Hook does not guess that purpose from code it has not read.

## Installing for Claude Code and Codex

General hosts need Node.js 18 or later, per the README; Pi 0.84.4 itself requires Node.js 22.19 or later. Full per-host steps live in INSTALL.md. For Claude Code, run these from the repository root after extracting it:

```bash
claude plugin validate .
claude plugin marketplace add ./
claude plugin install stop-that-shit@stop-that-shit
```

Restart Claude Code or run /reload-plugins. You then invoke the namespaced Skill, for example /stop-that-shit:stop-that-shit review -- followed by your instruction.

Codex installs from the marketplace with an explicit version tag. The README notes that --ref 0.2.1 pins the install to a version tag rather than following the mutable main branch:

```bash
codex plugin marketplace add lennney/stop-that-shit --ref 0.2.1
codex plugin add stop-that-shit@stop-that-shit
```

After restarting Codex, type /hooks in the new CLI TUI, inspect the commands, and trust UserPromptSubmit and PreToolUse. The repository also ships INSTALL_FOR_AGENTS.md, which the README says can be handed to Codex to perform the non-interactive steps.

## OpenCode, Hermes and Pi in practice

OpenCode 1.18.18 or later can install the repository globally without cloning it:

```bash
opencode plugin github:lennney/stop-that-shit -g
```

After a restart, set the contract with $stop-that-shit review -- and your instruction. One caveat the README states plainly: that command installs the Guard, but the bundled Skill and the optional /sts alias are not registered automatically, so check INSTALL.md before assuming the Skill is active.

Hermes Agent CLI needs Node.js 18 or later and a two-step enable. The plugin is installed disabled and then enabled explicitly:

```fish
hermes plugins install lennney/stop-that-shit/.hermes-plugin --no-enable
hermes plugins enable stop-that-shit
hermes plugins list
```

CLI users must start a new Hermes process or session; Gateway users run hermes gateway restart. The README is specific that this restart is only needed after enabling, disabling, updating, rolling back or reinstalling the plugin, not on every use.

Pi is the tightest constraint. The adapter is verified against @earendil-works/pi-coding-agent 0.84.4, installed from a local checkout containing the adapter, and invoked as /skill:stop-that-shit review --. Installing from the 0.2.1 tag gets you the Pi Adapter and both Skills.

## The default state does not block anything

This is the limitation most likely to disappoint a first-time user. After installation the Guard sits in OBSERVING / unconfirmed: it inspects and records covered actions, but it will not guess your task authorization and will not return a permission deny. Enforcement is something you arm by declaring a mode, not something you get by installing.

The second limitation is coverage. The Guard only checks Hook paths the host actually exposes, which is why the repository carries HOST-ADAPTER-CONTRACT.md alongside ARCHITECTURE.md. If your workflow runs the agent somewhere outside those paths, the Guard is not in the loop at all.

A third is the narrow files= boundary. Release 0.2.1 was a fix release for false allows in that area: absolute paths and host-reported relative paths are now compared uniformly with original casing preserved, unknown tools or actions whose target path cannot be proven now request approval under a narrow files= boundary, and an empty files= value no longer degrades into unlimited scope. Five boundary scenarios have regression tests. The direction of travel is toward asking for approval rather than silently allowing, which means a narrow contract can produce more interruptions, not fewer. If you do not know the full set of affected files, the README advises against writing files= at all and letting the agent follow the real call chain.

## Where it sits next to HERO and next to AGENTS.md

The README credits HERO (HERO-Anti-OverDefense) for the digest criterion: a summary must replace a more expensive operation and its result must control the next step. HERO is the closest reference point for the hashing rule, and the difference in approach matters. HERO is cited as the source of the judgement criterion, while Stop That Shit wraps that criterion into host-specific Hooks that can return a permission deny inside Codex, Claude Code, OpenCode, Hermes Agent CLI and Pi. A prose rule in a prompt file cannot deny a tool call; a Hook can, on the paths it covers.

The other alternative is the one most readers already have: a long AGENTS.md. That approach is free, works in any host, and needs no Node runtime or plugin trust step. Its failure mode is the one the README describes from experience: rules accumulate, the file becomes its own maintenance burden, and nothing enforces them at the tool-call level. Stop That Shit trades that for per-host installation, a version pin you should keep, and a contract you have to write before the Guard does anything.

## Version pinning, licence and the cost of upgrades

The project is MIT licensed, and package.json is marked private with version 0.2.2. The Codex install example pins --ref 0.2.1, which tells you the intended upgrade discipline: you move the tag deliberately rather than tracking main.

The upgrade cost is concentrated in two places. First, host compatibility: Pi is pinned to @earendil-works/pi-coding-agent 0.84.4, and OpenCode requires 1.18.18 or later, so a host upgrade can invalidate the adapter. Second, the Guard's own boundary semantics can change between patch releases, as 0.2.1 shows for files= handling. If you rely on a narrow files= contract, re-read the changelog before bumping, because a fix that makes the Guard stricter can turn previously allowed actions into approval requests.

On the licence: MIT permits commercial use and modification, and the repository also ships PRIVACY.md and SECURITY.md. Nothing in the README suggests a hosted component or telemetry, and the topic list includes local-first. That is a description of the project, not legal advice for your organisation.

## Conclusion

Adopt it if you already run Codex, Claude Code, OpenCode, Hermes Agent CLI or Pi and you keep rewriting the same prohibitions into AGENTS.md. Skip it if you want a tool that decides for you what counts as overengineering: the README is explicit that the Guard does not guess task authorization, and the default state is OBSERVING / unconfirmed, which records covered actions without denying anything. Before trusting it, read HOST-ADAPTER-CONTRACT.md to check whether your host is a covered Hook path, confirm your Node version against the INSTALL.md requirement for that host, and try one narrow contract such as review -- on a real diff to see what the Guard actually intercepts.

## FAQ

### What does "stop" mean in Stop That Shit?

It refers to the Guard returning a denial for a covered tool call that falls outside the task contract, rendered in the README as a red stamp reading STOP / INTENT with a reason such as MODE_FORBIDS_MUTATION. It is not a general-purpose kill switch for the agent.

### Does Stop That Shit block the agent immediately after installation?

No. The README states that after installation the Guard is in OBSERVING / unconfirmed: it inspects and records covered actions but does not guess task authorization and does not return a permission deny. Enforcement comes from declaring a mode such as review or change.

### Which AI coding agents does Stop That Shit support?

The README lists five adapters sharing one task-boundary core: Codex, Claude Code, OpenCode, Hermes Agent CLI and Pi. Installation differs per host and is documented in INSTALL.md.

### Why does Stop That Shit deny hash operations by default?

The README says a Hook can identify hash actions with relatively high confidence in supported tool calls, and applies the HERO criterion that a digest must replace a more expensive operation and control the next step. You can pass hash=allow when the user asked for the checksum or the repository's code and release process require it.

## Sources

- [lennney/stop-that-shit on GitHub](https://github.com/lennney/stop-that-shit)
- [License: MIT](https://github.com/lennney/stop-that-shit/blob/main/LICENSE)
- [Project website](https://take-a-deep-breath0.com/zh/stop-that-shit)
- [README](https://github.com/lennney/stop-that-shit/blob/main/README.md)
- [Releases](https://github.com/lennney/stop-that-shit/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/lennney-stop-that-shit
