agentic_security vs stop-that-shit
The two are close in size: 2.0k stars for agentic_security, 1.6k for stop-that-shit.
They split the axes: agentic_security leads on model freedom and setup ease, stop-that-shit on context depth.
Stars and commit dates come from our own daily tracking. The six axes are read off each project's documentation by our review pipeline, so they describe what a project says about itself, not what we measured in its code.
Where they stand today
Agentic Security focuses on agent/workflow-focused, multimodal (text, image, audio) and multi-step attack/fuzzing capabilities (including RL-based and dataset mutation approaches) to evaluate LLM vulnerabilities beyond single-shot prompt tests.
- Stars
- 2.0k
- Tracked growth
- +4.7%
- Maturity
- ●●●●●
- Last commit
- 3d ago
- Language
- Python
- License
- Apache-2.0
- Cost to run
- Your LLM API key, usage billed by the provider
Implements executable, evidence-backed Guards and Skills that intercept unrequested hashes, dependency/subagent launches and scope creep across multiple agent hosts, turning policy statements into machine-enforceable checks.
- Stars
- 1.6k
- Tracked growth
- not tracked long enough
- Maturity
- ●●●●●
- Last commit
- 2d ago
- Language
- JavaScript
- License
- MIT
- Cost to run
- Free, local install; uses the host agent's model access (may require provider subscriptions).
Six axes, head to head
Each axis runs 0 to 5. The label under a score is what that project's own docs claim, not a category average.
| Axis | agentic_security | stop-that-shit |
|---|---|---|
Context depth How much of your codebase it sees before it answers: the open diff, the diff plus related files, or the whole repository. | ●●●●● Prompt-only | ●●●●● Diff + related files |
Noise control How it keeps output volume down — severity thresholds, deduplication, incremental runs over new commits only. | ●●●●● Thresholds/config | ●●●●● Armed / observing gating |
Customization How far it bends to your team: custom rules, prompts, style guides, per-path config. | ●●●●● Config + modules | ●●●●● Command flags & policies |
Privacy Whether your code stays on your own infrastructure: fully local, self-hostable, or cloud API only. | ●●●●● Self-hostable | ●●●●● Self-hostable |
Model freedom Whether you can point it at any provider, or it is wired to one. | ●●●●● Bring-your-own-key | ●●●●● Multiple specific providers |
Setup ease What it takes to get a first useful run out of it. | ●●●●● One-command start | ●●●●● Install + restart |
Which one to pick
Pick agentic_security if…
Easy setup — pip-installable and runnable locally with configurable datasets and modules to quickly run multimodal, multi-step vulnerability scans against your LLM endpoints.
- Model freedom: Bring-your-own-key (5/5 against 3/5)
- Setup ease: One-command start (5/5 against 3/5)
Pick stop-that-shit if…
Privacy-first — a local-first plugin that enforces task-boundary guardrails across Codex, Claude Code, OpenCode and Hermes Agent CLI without relying on a centralized service.
- Context depth: Diff + related files (3/5 against 1/5)
What people want from each one
msoedov/agentic_security
Hacker News: Agentic Security – LLM Vulnerability Scanner drew 2 points and 0 comments.
lennney/stop-that-shit
Questions people ask
Is agentic_security better than stop-that-shit?
They split the axes: agentic_security leads on model freedom and setup ease, stop-that-shit on context depth. agentic_security is worth picking when easy setup — pip-installable and runnable locally with configurable datasets and modules to quickly run multimodal, multi-step vulnerability scans against your LLM endpoints.
Which of agentic_security and stop-that-shit keeps my code private?
agentic_security: Self-hostable (4/5). stop-that-shit: Self-hostable (4/5).
What does each one cost to run?
agentic_security: Your LLM API key, usage billed by the provider. stop-that-shit: Free, local install; uses the host agent's model access (may require provider subscriptions)..
Full profiles: msoedov/agentic_security and lennney/stop-that-shit. Everything else in Security & guardrails.