Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/rootbr/rooted/cleaning-codenpx skills add rootbr/rooted --skill cleaning-codegit clone --depth 1 https://github.com/rootbr/rootedWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00154 | $0.04377 |
| Opus 5 | $0.00077 | $0.02188 |
| Sonnet 5 | $0.00031 | $0.00875 |
| Haiku 4.5 | $0.00015 | $0.00438 |
Grade A, and why
cleaning-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 198 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Clean Code
Evidence base: Robert C. Martin, Clean Code: A Handbook of Agile Software Craftsmanship (2008) and Clean Architecture (2017); Martin Fowler, Refactoring: Improving the Design of Existing Code (1999); cleancoder.com. Chapter references cite Clean Code unless noted otherwise.
Load-bearing rule — maximum simplicity
Boy Scout Rule: leave every piece of code cleaner than you found it (Clean Code, Preface). Simple is the default; complexity earns its place against a specific constraint.
Functions (Ch 3)
- Small — "first rule: functions must be compact; second rule: functions must be even more compact." Aim 5–10 lines; 20 is already large; blocks inside
if/else/whileshould be one line, ideally a function call (Ch 3 "Small!" + "Blocks and Indenting", p. 34–35) - One thing — operational test: try to extract another function whose name isn't a paraphrase of the body. If the extraction is meaningful, the original did more than one thing (Ch 3 "Do One Thing" / "One Level of Abstraction", p. 36)
- 0–2 arguments ideal; 3 requires justification; more → group into an object ("Function Arguments")
- No boolean flags — a flag argument hides two functions in one; split them ("Flag Arguments")
- No side effects — what the name doesn't promise, the body doesn't do ("Side Effects")
- Descriptive name — a long, clear verb beats a short, vague one ("Use Descriptive Names")
- Return the transformed value; don't mutate the argument —
Buffer transform(Buffer in)beatsvoid transform(Buffer out)(Ch 3 "Standard Unary Forms", p. 66) - Separate command from query — a method either does or answers, never both (Ch 3 "Command Query Separation", p. 45; Fowler Ch 10 "Separate Query from Modifier", p. 282)
- Treat parameters as
final; if you need to change the value, copy into a local (Fowler Ch 6 "Remove Assignments to Parameters", p. 144)
Names (Ch 2)
- Reveal intent — the name answers why this variable exists and how it is used
- Pronounceable —
generationTimestamp, notgenymdhms - No type encodings —
name, notstrName/m_name/userObj - Named constants —
DAYS_IN_WEEKbeats the literal7(magic numbers have no search anchor) - Searchable — the identifier is distinctive enough that grep finds exactly the intended use
- Don't disinform — never reuse
l/O(look like 1/0); never name a thingaccountListunless it is aList(Ch 2 "Avoid Disinformation", p. 19–20) - Pick one word per concept —
fetchORretrieveORget, not all three (Ch 2 "Pick One Word per Concept", p. 26) - Class names are nouns; method names are verbs — a
Manager/Processorclass name hints at an SRP violation (Ch 2 "Class Names" / "Method Names", p. 25)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 198 lines · 154 tokens per session scan A ad716b01f52a
cleaning-code is a skill published in the GitHub repository rootbr/rooted (21 stars, last pushed 26d ago), licensed Apache-2.0. It adds 154 tokens to every session and 4,377 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…