agent-governance-toolkit vs stop-that-shit

agent-governance-toolkit is much bigger: 6.2k stars against 1.6k.

They split the axes: agent-governance-toolkit leads on model freedom and setup ease, stop-that-shit on context depth.

Stars and commit dates come from our own daily tracking. The six axes are read off each project's documentation by our review pipeline, so they describe what a project says about itself, not what we measured in its code.

Where they stand today

Deterministic, application-level enforcement that intercepts every tool call and makes denied actions structurally impossible (fail-closed governance plus tamper-evident audit), rather than relying on prompt-level controls.

Stars
6.2k
Tracked growth
+51.2%
Maturity
Last commit
1d ago
Language
Python
License
MIT
Cost to run
Free, open-source

Implements executable, evidence-backed Guards and Skills that intercept unrequested hashes, dependency/subagent launches and scope creep across multiple agent hosts, turning policy statements into machine-enforceable checks.

Stars
1.6k
Tracked growth
not tracked long enough
Maturity
Last commit
2d ago
Language
JavaScript
License
MIT
Cost to run
Free, local install; uses the host agent's model access (may require provider subscriptions).
0%+240%90 tracked days
microsoft/agent-governance-toolkitlennney/stop-that-shit

Six axes, head to head

Each axis runs 0 to 5. The label under a score is what that project's own docs claim, not a category average.

Axisagent-governance-toolkitstop-that-shit
Context depth
How much of your codebase it sees before it answers: the open diff, the diff plus related files, or the whole repository.
Action-level only
Diff + related files
Noise control
How it keeps output volume down — severity thresholds, deduplication, incremental runs over new commits only.
Approval gating
Armed / observing gating
Customization
How far it bends to your team: custom rules, prompts, style guides, per-path config.
YAML & APIs
Command flags & policies
Privacy
Whether your code stays on your own infrastructure: fully local, self-hostable, or cloud API only.
Fully local runnable
Self-hostable
Model freedom
Whether you can point it at any provider, or it is wired to one.
Bring-your-own key
Multiple specific providers
Setup ease
What it takes to get a first useful run out of it.
One-command start
Install + restart

Which one to pick

Pick agent-governance-toolkit if…

Deterministic enforcement — pick AGT when you need fail-closed, application-level policy enforcement and tamper-evident auditing that prevents agents from performing denied actions.

  • Model freedom: Bring-your-own key (5/5 against 3/5)
  • Setup ease: One-command start (5/5 against 3/5)
Runs in pr-bot, github-action, ci, cli, ide, coding-agent-plugin, web-app. Works with byok.

Pick stop-that-shit if…

Privacy-first — a local-first plugin that enforces task-boundary guardrails across Codex, Claude Code, OpenCode and Hermes Agent CLI without relying on a centralized service.

  • Context depth: Diff + related files (3/5 against 1/5)
Runs in cli, coding-agent-plugin. Works with openai, anthropic, other-fixed.

What people want from each one

Questions people ask

Is agent-governance-toolkit better than stop-that-shit?

They split the axes: agent-governance-toolkit leads on model freedom and setup ease, stop-that-shit on context depth. agent-governance-toolkit is worth picking when deterministic enforcement — pick AGT when you need fail-closed, application-level policy enforcement and tamper-evident auditing that prevents agents from performing denied actions.

Which of agent-governance-toolkit and stop-that-shit keeps my code private?

agent-governance-toolkit: Fully local runnable (5/5). stop-that-shit: Self-hostable (4/5).

What does each one cost to run?

agent-governance-toolkit: Free, open-source. stop-that-shit: Free, local install; uses the host agent's model access (may require provider subscriptions)..

Full profiles: microsoft/agent-governance-toolkit and lennney/stop-that-shit. Everything else in Security & guardrails.