Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cosmix/loom/loom-dead-code-checknpx skills add cosmix/loom --skill loom-dead-code-checkgit clone --depth 1 https://github.com/cosmix/loomWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cosmix/loom/loom-dead-code-check)<a href="https://agentmods.dev/skills/cosmix/loom/loom-dead-code-check"><img src="https://agentmods.dev/badge/skills/cosmix/loom/loom-dead-code-check.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00029 | $0.02503 |
| Opus 5 | $0.00015 | $0.01252 |
| Sonnet 5 | $0.00006 | $0.00501 |
| Haiku 4.5 | $0.00003 | $0.00250 |
Grade A, and why
loom-dead-code-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 170 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dead Code Detection
Overview
Dead code — written but never called, imported, or used — is a direct signal of incomplete integration: a function nothing calls means the feature isn't wired up. In loom it serves two roles: wiring verification (catch implemented-but-unintegrated code) and code quality (cleanup). Most valuable in integration-verify stages as a final gate over all implementation stages.
⚠️
truthsis GONE as a standalone field. Put dead-code checks in the first-classdead_code_checkfield (a goal-backward layer, run byloom check) or inacceptance(a build/lint command that exits non-zero on findings). A top-leveltruths:block is rejected as an unknown field.
If dead code survives implementation it usually means: feature not wired (command unregistered, route unmounted), test code never run, refactor leftovers, or an incomplete implementation.
The dead_code_check field (preferred, first-class)
dead_code_check is a goal-backward check evaluated by loom check <stage-id>. Schema:
dead_code_check:
command: "cargo build --message-format=short 2>&1"
fail_patterns: ["warning: unused", "is never read", "never constructed"]
ignore_patterns: ["generated.rs", "#[allow(dead_code)]"]
Exactly how loom evaluates it (verify/goal_backward/dead_code.rs):
- Runs
commandinworking_dir, 120 s timeout, capturing stdout and stderr. - Scans the combined output line by line.
- A line is a violation if it contains any
fail_pattern(plain substring, not regex) AND contains noignore_pattern. - Each violating line becomes one gap.
⚠ The command's exit code is ignored — only output text matters. So cargo build (exit 0 with warnings) works fine; you do NOT need -D warnings. This is the key difference from an acceptance command, which passes/fails on exit code.
⚠ ignore_patterns match the whole output line, so you can suppress by symbol name, file path, or an #[allow(...)] echo — whatever appears on the tool's line. Substring, so old_helper also ignores old_helper_2.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · -29 tokens per session 39d9120eb879
- 4d ago First seen · 170 lines · 58 tokens per session scan A e4bf48b1503a
loom-dead-code-check is a skill published in the GitHub repository cosmix/loom (54 stars, last pushed today), licensed MIT. It adds 29 tokens to every session and 2,503 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
hardcoded-secret
A bundle that leaks a real credential. This must never publish.
code-review
Perform thorough code reviews focusing on correctness, security, and maintainability.
checkpointed-workflow
Use when the user asks to assemble and validate a checkpointed report bundle.
deterministic-transform
Use when the user asks to transform a JSON data file deterministically.
document-formatter
Use when the user asks to format a document against the house style guide.
dangerous-skill
Example skill that demonstrates security scanner detection.