Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/iwritec0de/wp-dev/php-cleanupnpx skills add iwritec0de/wp-dev --skill php-cleanupgit clone --depth 1 https://github.com/iwritec0de/wp-devWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00157 | $0.03700 |
| Opus 5 | $0.00078 | $0.01850 |
| Sonnet 5 | $0.00031 | $0.00740 |
| Haiku 4.5 | $0.00016 | $0.00370 |
Grade A, and why
php-cleanup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 443 lines — stays where its author put it; the contents beside it link to each section on GitHub.
PHP/WordPress Dead Code & Dependency Cleanup
A toolchain that replicates what Knip does for JS/TS — detect unused code, unused dependencies, missing dependencies, and dead exports — but for PHP/WordPress plugin and theme development.
Toolchain Overview
| Tool | Purpose | Detects |
|---|---|---|
composer-unused |
Unused Composer packages | Packages in require/require-dev never referenced in code |
composer-require-checker |
Missing Composer packages | Packages used in code but not declared in composer.json |
Psalm --find-unused-code |
Dead PHP code | Unused classes, methods, functions, properties, variables |
| PHP-CS-Fixer | Unused use imports |
use statements at the top of files that aren't referenced |
| PHP_CodeSniffer | Unused imports (alt) | Same as above, alternative tool |
Installation
All Tools at Once
composer require --dev \
icanhazstring/composer-unused \
maglnet/composer-require-checker \
vimeo/psalm \
php-stubs/wordpress-stubs \
friendsofphp/php-cs-fixer
Individual Installation
# Unused dependency detection
composer require --dev icanhazstring/composer-unused
# Missing dependency detection
composer require --dev maglnet/composer-require-checker
# Static analysis + dead code detection
composer require --dev vimeo/psalm
composer require --dev php-stubs/wordpress-stubs
# Unused import cleanup
composer require --dev friendsofphp/php-cs-fixer
Tool 1: composer-unused — Unused Dependencies
Detects Composer packages listed in composer.json that are never referenced anywhere in the codebase.
Usage
# Basic scan
composer unused
# JSON output for parsing
composer unused --output-format=json
# Exclude specific packages from the check
composer unused --excludePackage=php-stubs/wordpress-stubs
# Only check runtime dependencies (skip dev)
composer unused --no-dev
Configuration (composer-unused.php)
<?php
declare(strict_types=1);
use ComposerUnused\ComposerUnused\Configuration\Configuration;
use ComposerUnused\ComposerUnused\Configuration\NamedFilter;
use ComposerUnused\ComposerUnused\Configuration\PatternFilter;
return static function (Configuration $config): Configuration {
return $config
// Packages used dynamically or via WordPress hooks
->addNamedFilter(NamedFilter::fromString('php-stubs/wordpress-stubs'))
->addNamedFilter(NamedFilter::fromString('wpackagist-plugin/some-plugin'))
// Ignore all packages matching a pattern
->addPatternFilter(PatternFilter::fromString('/^ext-/'));
};
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 443 lines · 157 tokens per session scan A 6ec00fbad869
php-cleanup is a skill published in the GitHub repository iwritec0de/wp-dev (1 stars, last pushed 4mo ago), licensed MIT. It adds 157 tokens to every session and 3,700 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…