Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cofin/flow/debloatnpx skills add cofin/flow --skill debloatgit clone --depth 1 https://github.com/cofin/flowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00030 | $0.00897 |
| Opus 5 | $0.00015 | $0.00449 |
| Sonnet 5 | $0.00006 | $0.00179 |
| Haiku 4.5 | $0.00003 | $0.00090 |
Grade A, and why
debloat scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Debloat
Reduce the semantic surface a maintainer must understand without changing what users can observe. Deletion is a behavior-preserving refactor, not proof that the deleted material was unnecessary.
Operating mode
- For a review, inspect and report evidence-backed findings only. Do not edit.
- For a change request, implement the smallest coherent cleanup and verify it.
- Read repository instructions, task state, and relevant architecture guidance first.
- Inspect the worktree before editing and preserve user and other-agent changes.
- Keep public API removals, compatibility breaks, dependency changes, and broad redesigns out of scope unless explicitly authorized.
Workflow
1. Establish scope and invariants
Identify the contracts that must remain stable:
- runtime behavior and error semantics;
- public imports, signatures, serialization shapes, and configuration;
- supported versions and optional-dependency boundaries;
- performance-sensitive paths;
- test coverage and repository quality gates.
Use call-site tracing to classify each candidate as public, private-live, private-dead, generated, or test-only. Check direct calls, re-exports, registration, reflection, configuration strings, generated references, docs, and tests before declaring code dead.
2. Capture a proportional baseline
Run focused verification before editing. Observable behavior and bug fixes use the task's TDD strategy. Behavior-preserving deletion, consolidation, or reordering uses a green-before/green-after characterization baseline. Read test and gate debloat before deleting tests or replacing a gate.
3. Simplify
- Remove wrappers only when they add no contract, dispatch, instrumentation, or type boundary.
- Preserve explicit code when consolidation would create condition-heavy or overly generic abstractions.
- Remove historical narration, phase labels, stale TODOs, and comments that merely restate code.
- Preserve rationale for non-obvious constraints, external quirks, security properties, and rejected alternatives.
- Treat repository-defined instruction comments such as
ai:as user instructions. - Prefer behavior-oriented tests and native lint, type, parser, or build rules over implementation snapshots and ad hoc source scanners.
- Keep structural tests when structure is operationally meaningful, including memory layout, hashing, compilation, reflection, serialization, signatures, and supported exports.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 76 lines · 30 tokens per session scan A 645812866ff4
debloat is a skill published in the GitHub repository cofin/flow (15 stars, last pushed 3d ago), licensed Apache-2.0. It adds 30 tokens to every session and 897 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
subagent-driven-development
Use when executing implementation plans with independent tasks in the current session.
write-documentation
Use when writing or substantially rewriting human-facing prose: documentation, README, guides, blog posts, emails, Slack messages, PR descriptions, release notes, or any text a human will read. Not for code comments, commit messages, or agent-to-agent communication.
document-release
Use when implementation on a branch is complete and it is about to be merged or PR'd — or when finishing-a-development-branch reaches its docs-audit gate — and after code changes are committed, to ensure all project documentation accurately reflects shipped code. Covers README, ARCHITECTURE, CONTRIBUTING, CHANGELOG…
finishing-a-development-branch
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup.
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
writing-plans
Use when you have a spec or requirements for a multi-step task, before touching code.