stanley-code — security grade SAFE, quality 59/100

Security audit verdict: SAFE · quality 59/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by devagrawal09 · Agent Tool · ★ 87

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is stanley-code safe to install? View the security audit →

About stanley-code

Stanley A Jev-first, self-improving coding agent. Stanley is a command-line tool for checking and understanding code changes. Instead of naming a command, you describe what you need. TypeSafe Jev routes the request to one workflow: a built-in, a trusted repository workflow, or one Stanley wrote for itself. Each workflow is deterministic code that gathers bounded evidence and asks Jev small fixed-choice questions about it; code, not a model, makes the decisions. That is the hot path, and it never starts a general agent. When no workflow supports a request, Stanley falls back to the Pi coding agent if it is installed, reports the agent's own account of what it did without claiming to have verified it, and then, in the background, asks an agent to write a Stanley workflow for that kind of request. The candidate is validated and staged; you promote it, and the next such request runs without any agent. Stanley was previously published as the placeholder package; see docs/decision-log.md. Get started Release status: is not on npm yet. This README describes , which is not released; until it is, build from source.

Quick Facts

Stars87
Forks6
LanguageTypeScript
CategoryAgent Tool
LicenseMIT
Quality Score59.4822409636294/100
Open Issues1
Last Updated2026-09-19
Created2026-09-17
Platformsnode
Est. Tokens~20k

Compatible Skills

These tools work well together with stanley-code for enhanced workflows:

  • jev-browser — semantic(0.48)+complementary+same_lang+similar_pop+shared_platform (67%)
  • jev-mcp — semantic(0.43)+complementary+same_lang+similar_pop+shared_platform (65%)

stanley-code alternative? Top 2 similar tools

Looking for a stanley-code alternative? If you're comparing stanley-code with other agent tool tools, these 2 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • tutor-skills by RoundTable02 · ⭐ 400

    A Claude Code skill that turns PDFs, docs, and codebases into Obsidian study vaults

  • repren by jlevy · ⭐ 374

    Power rename/refactor tool for CLI and agent use

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is stanley-code?

stanley-code is Bounded TypeSafe Jev workflows for coding agents.. It is categorized as a Agent Tool with 87 GitHub stars.

What programming language is stanley-code written in?

stanley-code is primarily written in TypeScript.

How do I install or use stanley-code?

You can find installation instructions and usage details in the stanley-code GitHub repository at github.com/devagrawal09/stanley-code. The project has 87 stars and 6 forks, indicating an active community.

What license does stanley-code use?

stanley-code is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to stanley-code?

The top alternatives to stanley-code on Agent Skills Hub include tutor-skills, repren. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools