Stop That Shit
lennney/stop-that-shit
Hook and skill guard that stops AI coding agents from unrequested checksums and scope creep
Stop That Shit is a hook and skill guard for AI coding agents that blocks unrequested hashes, checksums and task-scope creep. It includes a plugin for the Hermes Agent CLI alongside versions for Codex, Claude Code, OpenCode and Pi.
What Stop That Shit does
Stop That Shit, abbreviated STS, targets four habits it calls SHIT: scope creep, hashing and hypothetical hardening, intent violation, and task thrashing. Examples from the README include writing a SHA-256 file nobody reads, editing files during a read-only review, and rerunning checks that already answered the question. The guard keeps necessary work, such as updating callers and migrating published data, and trims extras that serve no current purpose.
It ships as a Skill plus a Guard hook for Codex, Claude Code, OpenCode, the Hermes Agent CLI and Pi. A skill-only install is available for people who do not want execution blocking. The README cites 18 public Bad/Good test cases, with evidence and paired Codex runs documented in the repository. Setting hash=allow lets a checksum through when a release process really reads it. The README is mainly in Chinese, with English and Korean versions.
Key features
- Skill plus hook guard aimed at scope creep, unused hashing, intent violations and task thrashing
- Hermes Agent CLI plugin installed with hermes plugins install and turned on with hermes plugins enable
- Hosts covered: Codex, Claude Code, OpenCode, Hermes Agent CLI and Pi
- Skill-only install for the rules without execution blocking
- 18 public Bad/Good judgement cases plus a recorded evidence file
- hash=allow override for checksums that a release process reads
When to use it
- Keep a Hermes Agent coding session from adding unrequested checksum files
- Hold a read-only review to reporting problems instead of editing files
- Stop an agent from re-running tests and reviews that already answered the question
Who it is for: Developers who run AI coding agents and want fewer unrequested changes and repeated checks.
How it fits with Hermes Agent
The repository includes a plugin for the Hermes Agent CLI under .hermes-plugin; gateway users restart the gateway after enabling it.
How to install Stop That Shit
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
hermes plugins install lennney/stop-that-shit/.hermes-plugin --no-enable
hermes plugins enable stop-that-shit
hermes plugins listRequirements: Node.js 18+ for the Hermes Agent CLI plugin
FAQ
What is Stop That Shit?
Stop That Shit is a skill and hook guard for AI coding agents. It stops unrequested hashes, checksums, scope creep and repeated checks while keeping work that is actually needed.
Does Stop That Shit work with Hermes Agent?
Yes. The repository includes a Hermes Agent CLI plugin. After enabling it, CLI users start a new Hermes process or session, and gateway users run hermes gateway restart.
How do I install Stop That Shit for Hermes Agent?
Run hermes plugins install lennney/stop-that-shit/.hermes-plugin --no-enable, then hermes plugins enable stop-that-shit. The command hermes plugins list shows the result.
Similar security for Hermes Agent
All securityHook that blocks dangerous git and shell commands before AI coding agents run them
LoRexxar KunLun-MOpen-source static code security scanner with a built-in skill for AI agents including Hermes
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
SafeAI-Lab-X ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
Related guides: How to run Hermes Agent securely