Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/samibs/skillfoundrynpx agentmods add skills/samibs/skillfoundry/pruneWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/samibs/skillfoundry/prune)<a href="https://agentmods.dev/skills/samibs/skillfoundry/prune"><img src="https://agentmods.dev/badge/skills/samibs/skillfoundry/prune.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00034 | $0.00825 |
| Opus 5 | $0.00017 | $0.00413 |
| Sonnet 5 | $0.00007 | $0.00165 |
| Haiku 4.5 | $0.00003 | $0.00082 |
Grade A, and why
prune scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the Prune agent — a dead-code and duplication remover. You find unused imports, unused exports, and copy-paste blocks, and remove the safe subset while reporting the rest for human judgement. You back your work with a real detection engine, not guesswork, and you never delete code you cannot prove is dead.
Persona: See agents/prune.md for full persona definition.
Operating modes
/prune Scan the current project (duplicates + dead code), report
/prune scan [--path <dir>] [--deep] Full scan; --deep also runs jscpd/knip/depcheck if present
/prune duplicates [--min-lines N] Copy-paste blocks only (report — extraction is a refactor)
/prune deadcode [--fix] Unused imports/exports; --fix removes the SAFE subset only
All modes delegate to the detection engine:
bash scripts/prune-scan.sh scan --path <dir>
bash scripts/prune-scan.sh deadcode --path <dir> [--fix]
bash scripts/prune-scan.sh duplicates --path <dir> [--min-lines N]
What the engine reports
| Finding | Meaning | Default action |
|---|---|---|
UNUSED-IMPORT |
Every binding of an import statement is unused in that file | Safe to auto-remove (whole line) via --fix |
PARTIAL-IMPORT |
Some bindings unused, others used | Report only — trimming a binding list needs care; do it deliberately |
UNUSED-EXPORT |
An exported symbol is referenced nowhere in the tree | Candidate — verify it is not a public API, entry point, or dynamically referenced, then remove |
| Duplicate block | An N-line block appears in 2+ places | Report — propose extracting a shared function/module; do not blind-delete |
Removal rules (safety)
- Only fully-unused imports are auto-removed. Everything else is a candidate you confirm
before touching.
--fixnever removes duplicates or exports. - Never touch generated or vendored code — the engine already excludes
node_modules,dist,build,.next,vendor,__pycache__,*.min.js,*.d.ts. Do not override that. - Unused-export candidates are heuristic. Before removing one, confirm it is not: a public
package export, a framework entry point (
index,main, CLI, route handler), used via a string/dynamic reference, or consumed by tests. When in doubt, leave it and flag it. - Duplicates are refactors, not deletions. Propose extracting the shared block into one function/module and updating call sites — never delete one copy and leave a dangling caller.
- Verify after removing. Re-run the project's type-check/build/tests after any deletion. If anything breaks, the finding was a false positive — restore it.
- Confirm before deleting anything other than fully-unused imports, unless the user has explicitly asked for autonomous cleanup.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 69 lines · 34 tokens per session scan A 0cd3179a2646
prune is a skill published in the GitHub repository samibs/skillfoundry (12 stars, last pushed 2d ago), licensed MIT. It adds 34 tokens to every session and 825 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
systemic-issue-triage
Trigger: new issue, bug report, triage, backlog, issue flood, community report, root cause, dead-end, blocked user. Attack issues by root class, never one-by-one; fixes must shrink the system, not grow it.
issue-root-resolution
Trigger: root audit, atacar la raíz, issue roots, backlog roots, mechanism map, deletion-driven fix, resolver issues de raíz, close outdated issues. Audit and resolve issue clusters by verified root cause.
rdd-defect-workflow
Trigger: RDD, receipt-driven development, review authority, receipt/lineage, correction/recovery, delivery gate/kill switch, bounded review defects. Guide work.
ring:searching-code
Forensic code search and analysis with optional Chain of Draft (CoD) ultra-concise mode. Five-phase methodology (clarification, planning, execution, analysis, synthesis) with severity assessment. Use for targeted investigation of specific patterns, bugs, or vulnerabilities. Skip for broad architecture mapping (use…
ring:test-driven-development
Enforcing the RED-GREEN-REFACTOR loop: write one failing test and watch it fail, write minimal code to pass, then refactor green. Use when starting implementation of a new feature or bugfix, or writing any new production code. Requires pasted failure output as proof of RED; code written before its test must be…
incident-response
Incident management lifecycle — triage, communicate, mitigate, postmortem. Three modes — new (start incident), update (status update), postmortem (blameless RCA report).