Agent skill

Scope Creep Guard

by lennney in lennney/stop-that-shit

Keeps an agent focused on the requested work by applying a five-step ladder that checks for direct solutions, real gaps and speculative defenses before adding anything.

MITAuto-check passedAgent Workflows

Install Scope Creep Guard

skills CLI
$ npx skills add lennney/stop-that-shit --skill stop-that-shit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lennney/stop-that-shit stop-that-shit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lennney/stop-that-shit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/stop-that-shit .claude/skills/stop-that-shit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stop-that-shit
GitHub stars
2.5k
Used in
1 other repo
Token cost
~2k tokens
SKILL.md length
1,027 words
Files
2
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Keeps an agent focused on the requested work by applying a five-step ladder that checks for direct solutions, real gaps and speculative defenses before adding anything.

  • Works in 5 steps: Understand the current responsibility.… → Start with a direct solution. Check… → Expand to close a concrete gap. Identify… → …
  • Deciding whether extra hardening or a new safeguard is actually needed
  • SKILL.md covers Follow the Stop Ladder, Resolve uncertainty without…, Keep the deliverable focused and Respect the task mode, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill is advisory and works without the optional Guard hooks, though it admits it cannot guarantee model behavior; with the Guard installed the same directives gain machine-enforced boundaries on supported host action paths. Its aim is to meet the task's responsibilities in full while letting real needs, not hypothetical ones, drive complexity.

A five-step ladder guides each implementation choice: understand the requested result and the guarantees to keep, start from a direct solution using existing code and platform features, expand only to close a concrete gap, judge each defense by what it detects and changes, and verify with the project's own checks before finishing. Defenses that are redundant or too broad are removed within the task scope, while those that hide failures or duplicate side effects are repaired. Ordinary validation, retries or dependencies are not triggers on their own.

When your agent uses it

  • Deciding whether extra hardening or a new safeguard is actually needed
  • Reviewing a change for overengineering or scope creep
  • Breaking out of a repeated verification loop and finishing the task
  • Keeping to explicit task boundaries the user set

Example prompts

  • “Fix the date parsing bug in reports.py and don't add anything the task doesn't require.”
  • “Review my diff for speculative defenses that nobody asked for.”
  • “You have re-run the same checks three times. Decide what evidence is enough and wrap up.”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Understand the current responsibility. Establish the requested result,
  2. Start with a direct solution. Check suitable code already in the project,
  3. Expand to close a concrete gap. Identify the supported input, consumer,
  4. Judge defenses by their effect. Identify what a mechanism detects and
  5. Verify the result and finish. Use the project's intended checks for the

What it can do on your machine

Read from SKILL.md and the folder at commit 694bbd5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scope Creep Guard loads about 2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,027 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lennney/stop-that-shit at commit 694bbd5, republished under its MIT licence (© lennney). 1,027 words, ~2,050 tokens.

Download SKILL.mdSave it as .claude/skills/stop-that-shit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
stop-that-shit
description
Complete requested work while preventing speculative defenses and scope creep. Use when considering extra hardening, reviewing possible overengineering, resolving repeated verification loops, following explicit task boundaries, or when the user invokes Stop That Shit. Ordinary use of validation, retries, or dependencies alone is not a trigger.
license
MIT

Stop That Shit

Meet the task's responsibilities in full. Let real needs drive complexity.

This Skill is advisory and works without the Guard hooks. It cannot guarantee model behavior. When the Guard is installed, the same directives also provide machine-enforced boundaries on supported host action paths.

Follow the Stop Ladder

Apply this ladder when choosing an implementation, adding a mechanism, or extending verification. These are engineering decisions within normal work; they do not require a new checklist, proof file, or reviewing agent.

  1. Understand the current responsibility. Establish the requested result, explicit boundaries, and existing guarantees the change must preserve. Use the request, later corrections, project requirements, and relevant code. Trace affected callers and failure paths before choosing a fix. Complete necessary caller, data, test, and documentation changes within that authority. A plan or an easier subset does not fulfill the requested result.
  2. Start with a direct solution. Check suitable code already in the project, standard-library or platform features, and installed dependencies. Compare actual behavior, failure handling, and state lifetime. Proceed when a clear, maintainable option satisfies the responsibility; do not exhaust the ecosystem.
  3. Expand to close a concrete gap. Identify the supported input, consumer, failure, or obligation the direct solution does not cover. Adapt or implement that missing behavior at the responsible layer. Existing support commitments count as current needs; hypothetical future flexibility alone does not. A larger diff is justified when it completes the affected flow.
  4. Judge defenses by their effect. Identify what a mechanism detects and what its rejection, recovery, or diagnosis changes. Keep effective protection. Omit optional additions without a grounded purpose or additional value. Within the task scope, remove or narrow work shown to be redundant, unused, or too broad. Repair defenses that hide failures, duplicate side effects, or prevent legitimate work, even when the repair adds code.
  5. Verify the result and finish. Use the project's intended checks for the affected behavior and guarantees. Honor explicit acceptance criteria and mandatory checks. Reuse evidence while it remains valid for the final state. Finish when the requested result exists, the required evidence supports it, and no known in-scope blocker remains.

Resolve uncertainty without inventing work

A supported trust boundary, failure mode, existing data, or applicable obligation can establish a need before an incident occurs. Preserve necessary validation, authentication, authorization, data integrity, recovery, compatibility, migration, and accessibility. Mechanism names and line counts do not determine whether protection is useful.

New optional work without a purpose can wait. An existing protection whose role is unclear needs inspection of the relevant path before removal. Missing evidence is not proof that it is unnecessary. Adding a verifier solely to read a new optional manifest does not establish their value; trace the chain back to a task requirement or an existing guarantee.

For example, a release consumer can make a checksum necessary. A TTL requirement can require more than an available cache provides. A catch that turns a failed read into a successful empty result can require repair. Choose from the actual contract and behavior in each case.

Resolve ordinary choices from available context. Ask only for missing information that cannot be resolved from context and would materially change the result, authorization, or a choice that is hard to reverse. Do not request authorization already given.

Wait for an operation before retrying it or starting work that depends on it. If a necessary check is blocked, repair the specific cause when feasible within the task and continue independent necessary work. Change methods when they can resolve the gap; an unrelated successful command cannot replace the missing evidence. Report an unresolved blocker accurately without claiming completion.

Show full SKILL.md (420 more words)Show less

Keep the deliverable focused

Report the result and relevant verification. Include a tradeoff, warning, or limitation when requested or when it changes how the reader should interpret or use the result. Put required disclosure at the decision point. Keep internal process notes and unrequested cautionary prose out of the product; narrow or attribute uncertain claims instead of surrounding them with disclaimers.

Respect the task mode

  • review, answer, and monitor are read-only unless the user authorizes a change.
  • change permits only requested work and necessary consequences.
  • Necessary work does not override an explicit file lock or a narrower action boundary. Explain a required boundary change before acting outside it.

With Skill only, treat the mode as an instruction. With the Guard installed, use the host-native invocation form.

Claude Code plugin:

text
/stop-that-shit:stop-that-shit change -- Fix the failing config test.
/stop-that-shit:stop-that-shit review -- Review this diff. Report findings; do not edit.

Codex plugin or host-neutral directive at the start of a prompt:

text
$stop-that-shit change -- Fix the failing config test.
$stop-that-shit review -- Review this diff. Report findings; do not edit.

Submit one directive on the first non-empty line, outside quotes and code blocks. Put task text after --, : , or a newline. Embedded examples do not set directive fields. Unknown fields or conflicting values leave the previous contract unchanged and require a corrected directive.

An installed Guard begins in observation-only unconfirmed mode. Do not claim that an action was blocked unless an explicit mode armed the Guard and the Guard returned a host-specific denial. Even then, describe the host effect as unobserved.

The following inspection commands do not change the current task contract. In Claude Code, pass the text after the namespaced slash command; in Codex, use the $stop-that-shit form shown below.

text
$stop-that-shit status
$stop-that-shit runtime
$stop-that-shit explain evt_...
$stop-that-shit label evt_... correct|incorrect|inconclusive

Use a hard file lock only when the complete boundary is already known:

text
$stop-that-shit lock change files=src/config.cjs|test/config.test.cjs -- Fix this behavior.

The active delegation limit is a session control:

text
$stop-that-shit change agents=N -- Run the task.

agents=N limits reserved concurrent capacity. It defaults to unlimited, and 0 forbids new delegation. A batch that exceeds the limit is rejected atomically. Request parameters do not prove completion: the host must confirm that a call did not execute, joined all its children, or ended an associated run. Unknown results keep their existing capacity; session-end alone does not prove completion. Permitted unbounded or unversioned resume calls remain unresolved until matching terminal evidence arrives. With unresolved activity, finite Guard requires that evidence or a new host session. Migration preserves valid budgets including 0. Lifecycle association uses explicit host identities, never event arrival order.

Claude Code equivalent:

text
/stop-that-shit:stop-that-shit lock change files=src/config.cjs|test/config.test.cjs -- Fix this behavior.

Do not invent a file list to appear precise. Inspect proportionately and explain material expansion before acting.

Finish

Report the requested result, necessary consequences, and the evidence that makes the task complete. Do not add a final audit loop only to satisfy this Skill.

© lennney, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/stop-that-shit of lennney/stop-that-shit.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 694bbd5

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in lennney/stop-that-shit, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Scope Creep Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scope Creep Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scope Creep Guard this skilllennney/stop-that-shit2.5k1 repos~2kAutomated safety check: PassMIT
Verification Before Completionduckbugio/flock502—~432Automated safety check: PassMIT
Validate Agent Workkryptamine/herdr-auto-title243—~605Automated safety check: PassMIT
Post-Feature Reviewjsmastery-pro/jsm-agent-skill218—~1.3kAutomated safety check: PassMIT
Harness Engineering GuideOdradekAI/harness-engineering-guide1251 repos~4.3kAutomated safety check: PassApache-2.0
Incremental Implementationaddyosmani/agent-skills103k1 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Has the agent build, test and lint a change, re-read the request and check for regressions before it says a coding task is done, then report exactly what it ran.

    502 GitHub stars~432 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Validate Agent Work

    kryptamine/herdr-auto-title

    Final checklist before handing work back in the herdr-auto-title repo: review the diff, run make check, apply the comment and AGENTS.md rules, then report.

    243 GitHub stars~605 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Post-Feature Review

    jsmastery-pro/jsm-agent-skill

    Compares a finished feature with its plan, the project's architecture and design rules, and production-readiness checks, then reports issues without fixing them.

    218 GitHub stars~1.3k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Harness Engineering Guide

    OdradekAI/harness-engineering-guide

    Audit, design, and implement AI agent harnesses for any codebase.

    125 GitHub starsUsed in 1 repo~4.3k tokens
    Agent WorkflowsAuto-check passed
  • Incremental Implementation

    addyosmani/agent-skills

    Delivers a change in thin vertical slices, each implemented, tested, verified and committed before the next, using vertical, contract-first or risk-first slicing.

    103k GitHub starsUsed in 1 repo~2.3k tokens
    Agent WorkflowsAuto-check passed
  • PUA Loop

    tanweai/pua

    Runs an unattended iterate-until-verified loop in which a user-set verify command, not the agent's own claim, decides when the task is finished.

    20k GitHub stars~1.1k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed

More from lennney/stop-that-shit

  • Defensive Writing Editor

    lennney/stop-that-shit

    Cuts defensive disclaimers, stacked hedging and self-protective narration from proposals and summaries, keeping only limits that affect the reader's decision.

    2.5k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed

Questions about Scope Creep Guard

What does Scope Creep Guard do?

Keeps an agent focused on the requested work by applying a five-step ladder that checks for direct solutions, real gaps and speculative defenses before adding anything. The skill is advisory and works without the optional Guard hooks, though it admits it cannot guarantee model behavior; with the Guard installed the same directives gain machine-enforced boundaries on supported host action paths. Its aim is to meet the task's responsibilities in full while letting real needs, not hypothetical ones, drive complexity.

When should I use Scope Creep Guard?

Scope Creep Guard fits situations like: deciding whether extra hardening or a new safeguard is actually needed; reviewing a change for overengineering or scope creep; breaking out of a repeated verification loop and finishing the task; keeping to explicit task boundaries the user set.

How do I install Scope Creep Guard in Claude Code?

Run `npx skills add lennney/stop-that-shit --skill stop-that-shit -a claude-code`. Or copy the skill folder (skills/stop-that-shit in lennney/stop-that-shit) into .claude/skills/stop-that-shit in your project. Claude Code loads it when a task matches its description.

How do I install Scope Creep Guard in Codex?

Run `npx skills add lennney/stop-that-shit --skill stop-that-shit -a codex`. Or copy the skill folder (skills/stop-that-shit in lennney/stop-that-shit) into .agents/skills/stop-that-shit in your project. Codex loads it when a task matches its description.

Can I use Scope Creep Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lennney/stop-that-shit --skill stop-that-shit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stop-that-shit, .gemini/skills/stop-that-shit, .github/skills/stop-that-shit and .opencode/skills/stop-that-shit in your project.

What does Scope Creep Guard need to run?

SKILL.md names no scripts, command-line tools or credentials: Scope Creep Guard is instructions for the agent only.

Does Scope Creep Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Scope Creep Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Scope Creep Guard use?

Scope Creep Guard is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scope Creep Guard use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Scope Creep Guard?

Skills that share tags, products or a category with Scope Creep Guard: Verification Before Completion (duckbugio/flock, 502 stars), Validate Agent Work (kryptamine/herdr-auto-title, 243 stars), Post-Feature Review (jsmastery-pro/jsm-agent-skill, 218 stars) and Harness Engineering Guide (OdradekAI/harness-engineering-guide, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scope Creep Guard?

lennney (a GitHub user) maintains it in lennney/stop-that-shit, which has 2,515 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 7, 2026.

Source: lennney/stop-that-shit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.