skill-cleaner

A report generator for auditing installed Codex or OpenClaw skills. It examines their usage, prompt size, duplicates, and enabled or disabled skill locations.

In plain words
What is it for?
Use it to measure skill budgets, inspect recent usage, find duplicate skills, and compare audits with or without logs or live data.
Why use it?
It helps find skills that consume too much context, overlap with one another, or are no longer useful. This gives you evidence for deciding what to shorten, disable, or remove.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/steipete/agent-scripts/skill-cleaner
Any agent
npx skills add steipete/agent-scripts --skill skill-cleaner
Clone the repo
git clone --depth 1 https://github.com/steipete/agent-scripts

Made for: Claude Code, Codex.

Per session 22 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 958 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00022 $0.00958
Opus 5 $0.00011 $0.00479
Sonnet 5 $0.00004 $0.00192
Haiku 4.5 $0.00002 $0.00096

Measured 2d ago against content hash 32e482ba1794, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

skill-cleaner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 2 executable files (scripts/skill-cleaner.test.ts, scripts/skill-cleaner.ts), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/skill-cleaner/SKILL.md · 62 lines

How it starts

The opening of the file, as written. The whole thing — 62 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Skill Cleaner

Use this when trimming skill prompt budget, finding duplicate skills, auditing enabled/disabled skill roots, or deciding which skills/plugins to remove.

Workflow

  1. Run the analyzer from this skill directory or repo root:
node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --months 3

Useful variants:

node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --no-logs
node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --no-live --no-logs
node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --months 6 --max-log-mb 800 --deep-logs
node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --context-tokens 272000 --budget-percent 2 --no-logs
node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --root ~/Dropbox/boxd/skills --no-logs
node --experimental-strip-types skills/skill-cleaner/scripts/skill-cleaner.ts --root ~/.agents/skills --root-only --no-logs
  1. Read the report in this order:
  • Skill Budget: live Codex inventory, 2% budget, budgeted usage, and full-description pressure.
  • Description candidates: long descriptions where relaxed grammar saves prompt budget.
  • Duplicates: same skill name or near-identical description/body across Codex, plugin cache, repo siblings, and personal skill roots.
  • Unused candidates: no recent user mention or actual SKILL.md read in recent Codex/OpenClaw logs.
  • Root summary: where skills came from and whether config marks them disabled.
  1. Before deleting or editing:
  • Verify the kept copy exists and is loaded.
  • Prefer deleting repo-local or agent-scripts duplicates when Codex built-ins cover them.
  • Keep repo-local OpenClaw maintainer skills when they encode repo policy or live operations.
  • Preserve trigger nouns in descriptions: product, tool, action, object.

Analyzer Notes

  • By default, codex debug prompt-input supplies the exact model-visible skill list, order, names, and aliased paths. --no-live forces the broader filesystem fallback.
  • The broad filesystem scan remains for duplicate, disabled, and archived-cache diagnostics; it is not treated as the loaded inventory.
  • The script mirrors Codex's model-visible line shape: - name: description (file: path).
  • It applies Codex-like frontmatter rules: YAML frontmatter only, default name from parent dir, single-line sanitized name and description.
  • It follows Codex core-skills/src/render.rs: 2% of raw context_window, token cost ceil(utf8_bytes / 4), then full descriptions -> equal description truncation -> omitted minimum lines. Alias-table line cost is included.
  • It reads ~/.codex/models_cache.json for GPT-5.5 context_window; fallback is 272,000 tokens and 2%.
  • It scans only normal Codex/plugin/repo skill roots by default. Extra folders such as Dropbox archives are included only with --root <path>.
  • --root-only requires at least one --root <path>, skips the live Codex inventory, and scans only those supplied roots.
  • It realpath-dedupes roots, so symlinked roots such as ~/.codex/skills/agent-scripts -> ~/Projects/agent-scripts/skills do not create false duplicates.
  • For duplicate names, it reports description/body similarity and suggests deletion candidates only when bodies are near copies. Keep priority defaults to direct Codex system skills, then direct Codex skills, then plugin skills, then personal/repo copies.
  • It scans ~/.codex/history.jsonl and recent ~/.codex/sessions/**/*.jsonl by default. Add --deep-logs for archived sessions and common OpenClaw/Clawd log folders.
  • Usage evidence is heuristic: user $skill/use skill mentions and paths observed in tool-call arguments.

Read the full file on GitHub · 62 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 62 lines · 22 tokens per session scan A 32e482ba1794

Subscribe to this mod's changes

skill-cleaner is a skill published in the GitHub repository steipete/agent-scripts (6,590 stars, last pushed today), licensed MIT. It adds 22 tokens to every session and 958 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

agent-host-chat-contributions

Build and review cross-cutting agent-host chat behavior through lifecycle contributions. Use when adding turn lifecycle side effects, prompt or context injection, restored-history transformation, protocol-action observation, or when reviewing changes that add code to AgentSideEffects or AgentService.

microsoft/vscode · 56 tokens

auto-perf-optimize

Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.

microsoft/vscode · 62 tokens