No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by devagrawal09 · Agent Tool · ★ 87
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is stanley-code safe to install? View the security audit →
Stanley A Jev-first, self-improving coding agent. Stanley is a command-line tool for checking and understanding code changes. Instead of naming a command, you describe what you need. TypeSafe Jev routes the request to one workflow: a built-in, a trusted repository workflow, or one Stanley wrote for itself. Each workflow is deterministic code that gathers bounded evidence and asks Jev small fixed-choice questions about it; code, not a model, makes the decisions. That is the hot path, and it never starts a general agent. When no workflow supports a request, Stanley falls back to the Pi coding agent if it is installed, reports the agent's own account of what it did without claiming to have verified it, and then, in the background, asks an agent to write a Stanley workflow for that kind of request. The candidate is validated and staged; you promote it, and the next such request runs without any agent. Stanley was previously published as the placeholder package; see docs/decision-log.md. Get started Release status: is not on npm yet. This README describes , which is not released; until it is, build from source.
| Stars | 87 |
| Forks | 6 |
| Language | TypeScript |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 59.4822409636294/100 |
| Open Issues | 1 |
| Last Updated | 2026-09-19 |
| Created | 2026-09-17 |
| Platforms | node |
| Est. Tokens | ~20k |
These tools work well together with stanley-code for enhanced workflows:
Looking for a stanley-code alternative? If you're comparing stanley-code with other agent tool tools, these 2 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
A Claude Code skill that turns PDFs, docs, and codebases into Obsidian study vaults
Power rename/refactor tool for CLI and agent use
Explore other popular agent tool tools:
stanley-code is Bounded TypeSafe Jev workflows for coding agents.. It is categorized as a Agent Tool with 87 GitHub stars.
stanley-code is primarily written in TypeScript.
You can find installation instructions and usage details in the stanley-code GitHub repository at github.com/devagrawal09/stanley-code. The project has 87 stars and 6 forks, indicating an active community.
stanley-code is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to stanley-code on Agent Skills Hub include tutor-skills, repren. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: