clean-shell

clean-shell is a skill for Claude Code, Codex from uwuclxdy/agenticat. It costs 30 tokens per session (519 once invoked), scanned A, original, MIT.

A set of rules for writing and testing Bash and POSIX shell scripts. Bash and POSIX shell are command-line scripting languages commonly used for automation.

In plain words
What is it for?
Use it for deployment scripts, system changes, remote commands, cleanup and rollback logic, ShellCheck setup, and Bats tests. Bats is a testing tool for shell scripts.
Why use it?
It reduces mistakes such as unquoted input, unsafe changes, incomplete cleanup, and scripts that behave differently after being run more than once.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/uwuclxdy/agenticat/clean-shell
Any agent
npx skills add uwuclxdy/agenticat --skill clean-shell
Clone the repo
git clone --depth 1 https://github.com/uwuclxdy/agenticat

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for clean-shell

README.md
[![agentmods](https://agentmods.dev/badge/skills/uwuclxdy/agenticat/clean-shell.svg)](https://agentmods.dev/skills/uwuclxdy/agenticat/clean-shell)
Your own site
<a href="https://agentmods.dev/skills/uwuclxdy/agenticat/clean-shell"><img src="https://agentmods.dev/badge/skills/uwuclxdy/agenticat/clean-shell.svg" alt="Measured on agentmods" height="20"></a>
Per session 30 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 519 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00030 $0.00519
Opus 5 $0.00015 $0.00260
Sonnet 5 $0.00006 $0.00104
Haiku 4.5 $0.00003 $0.00052

Measured 4d ago against content hash e5f363112f68, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

clean-shell scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/clean-shell/SKILL.md · 30 lines

What it actually says

Clean Shell

Shell-specific conventions for writing, hardening, reviewing, and testing scripts. The core rules below always apply. Load the one reference file matching the task; don't load them all.

Task touches File
Scripts that mutate live systems: deploy/apply, firewall/sshd/sudoers edits, systemd oneshot+timer units, ssh remote-exec, rollback, cleanup traps, idempotency references/defensive.md
.shellcheckrc, # shellcheck disable= directives, severity floors, exit codes, CI gating references/shellcheck.md
Bats tests: .bats files, run, setup/teardown, PATH-stub mocking, parallel jobs references/bats.md

Core Rules

  • Pick set flags by intent and comment the reason next to them: set -euo pipefail for orchestration where any failure aborts; drop -e when steps may fail without aborting; set -u alone for long-running loops. A thin wrapper sets no flags and ends with exec.
  • Quote every expansion ("$var", "${arr[@]}", "$(cmd)"); -- end-of-options guard before untrusted operands.
  • Validate input at the boundary into a checked value ("${1:?msg}", a case integer guard); no call site re-tests a raw string.
  • Every mktemp gets an EXIT trap right after creation. Traps are best-effort: SIGKILL, OOM-kill, and power loss skip them.
  • Anything that mutates system state is check-then-act idempotent; add flock where concurrent runs are possible.
  • Never echo a generated secret; set -x tracing and ps//proc/*/cmdline argv leak it too.
  • Every # shellcheck disable= carries a same-line reason comment.
  • Non-trivial scripts get bats tests covering the error paths, not just the happy path.
Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 30 lines · 30 tokens per session scan A e5f363112f68

Subscribe to this mod's changes

clean-shell is a skill published in the GitHub repository uwuclxdy/agenticat (5 stars, last pushed 5d ago), licensed MIT. It adds 30 tokens to every session and 519 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

archify

Create polished, validated architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as explorable standalone HTML with inline SVG, dark/light themes, optional trace motion, and PNG/JPEG/WebP/SVG/WebM export. Accept plain-language requirements or pasted Mermaid flowchart, sequenceDiagram, and…

tt-a1i/archify · 130 tokens

vox-director

Turn ONE topic into a finished Vox-style paper-collage explainer / ad video, end to end on the Atlas Cloud API + local ffmpeg — script, collage keyframes, motion, voice-over, music, captions, all automated. Use this whenever the user wants a "Vox style" video, a paper/torn-paper collage animation, a "motion collage"…

Alisa0808/vox-director · 236 tokens

social-post

學習使用者的 Facebook/Instagram/YouTube/Threads/X 語氣與受眾,規劃、撰寫、確認後發佈內容;以已登入 Chrome 受控掃描、草擬及回覆 FB/IG/Threads 留言;並作為流量、留存與轉化的結構化帳本。使用者說「發文」「用我的口氣」「回覆留言」「自動回留言」「掃留言」「查流量」「演算法」「把數據訓練進去」「比較貼文」「優化 pattern」時使用。.

Hao0321/claude-skill-social-post · 135 tokens

higgsfield

Use this skill whenever the user asks anything about Higgsfield AI — writing or refining video/image prompts, choosing a model (Kling, Sora 2, Veo, Wan, Seedance, Minimax Hailuo, DoP, Soul, Nano Banana, Seedream, Flux, GPT Image, etc.), camera controls, named motion presets, Soul ID character consistency, Cinema…

OSideMedia/higgsfield-ai-prompt-skill · 147 tokens

higgsfield-camera

Use when the user asks about camera movements, shot types, or how to describe camera behavior in a Higgsfield prompt. Contains all named camera controls with descriptions, best use cases, and example prompt phrases.

OSideMedia/higgsfield-ai-prompt-skill · 47 tokens

higgsfield-troubleshoot

Use when a Higgsfield generation fails, produces poor quality, looks wrong, doesn't match the prompt, or the user needs to fix or improve an output.

OSideMedia/higgsfield-ai-prompt-skill · 39 tokens