clean-skill-python

A small example skill for testing whether a Python-based skill follows expected safety rules. It formats a string and returns it without using the network or accessing unrelated files.

In plain words
What is it for?
Use it as a test fixture for SkillGuard, a tool that checks skill behavior and reports violations.
Why use it?
It provides a minimal case for checking that a skill passes validation with no findings.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/rudrendupaul/skillguard/clean-skill-python
Any agent
npx skills add RudrenduPaul/skillguard --skill clean-skill-python
Clone the repo
git clone --depth 1 https://github.com/RudrenduPaul/skillguard

Made for: Claude Code, Codex.

Per session 36 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 93 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00036 $0.00093
Opus 5 $0.00018 $0.00046
Sonnet 5 $0.00007 $0.00019
Haiku 4.5 $0.00004 $0.00009

Measured yesterday against content hash d0a529633791, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

clean-skill-python scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

The scan reads SKILL.md. This mod also ships 1 executable file (hooks/format_greeting.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

examples/clean-skill-python/SKILL.md · 13 lines

What it actually says

Clean Skill - Python (fixture)

This skill formats a string and returns it. It makes no network calls and does not read or write any files outside its own directory, matching what it declares above.

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 13 lines · 36 tokens per session scan A d0a529633791

Subscribe to this mod's changes

clean-skill-python is a skill published in the GitHub repository RudrenduPaul/skillguard (1 stars, last pushed 7d ago), licensed Apache-2.0. It adds 36 tokens to every session and 93 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

outrider-experimentation

Trigger, debug, and interpret Outrider Action runs on target repos as part of Claude-Code-driven paper-to-code work. Covers manual dispatch patterns, using remyxai-cli to scope paper search, fetching run logs and RUN SUMMARY JSON to interpret outcomes, checking GitHub coordination signals (existing PRs/Issues…

remyxai/outrider · 130 tokens

remyxai

Guidance for using remyxai-cli — managing research interests, querying paper recommendations, dispatching Outrider action runs, and running batched design-review cycles. Trigger when the user mentions Outrider, GitRank, paper recommendations, remyxai commands, or research-implementation workflows against a target repo.

remyxai/outrider · 76 tokens

pastewatch

Sensitive data scanner — deterministic detection and obfuscation for text content.

ppiankov/pastewatch · 16 tokens

migrationpilot

Check PostgreSQL DDL and migrations for lock and downtime hazards before writing or running them. Use before creating or editing any migration file, before writing CREATE INDEX / ALTER TABLE / DROP / ADD CONSTRAINT, and before running any migration command (psql, prisma migrate, alembic upgrade, flyway migrate, rails…

mickelsamuel/migrationpilot · 119 tokens

slop-chop

Remove AI writing tells from text with the slop-chop CLI. Use when the user wants to clean up a draft, strip em-dashes, semicolons, and stock buzzwords, enforce a spelling dialect, or make text read like a person wrote it instead of a chatbot. Also use before handing back a written draft, or to flag slop in Markdown…

dcadolph/slop-chop · 83 tokens

immunogen

Scan an AI-built ("vibe-coded") repo for launch-blocking issues — leaked secrets, exposed API keys, broken auth, missing row-level security, unsafe payment wiring, vulnerable dependencies, and risky AI-layer surface (skills/MCP servers/agent prompts). Returns a 0-100 Ship Score with a banded verdict and ranked…

Mocinjay/immunogen · 117 tokens