Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/xyruscode/ai-sync/de-claudenpx skills add XyrusCode/ai-sync --skill de-claudegit clone --depth 1 https://github.com/XyrusCode/ai-syncWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00111 | $0.04835 |
| Opus 5 | $0.00056 | $0.02417 |
| Sonnet 5 | $0.00022 | $0.00967 |
| Haiku 4.5 | $0.00011 | $0.00483 |
Grade A, and why
de-claude scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 274 lines — stays where its author put it; the contents beside it link to each section on GitHub.
de-claude: remove AI fingerprints from a repository
humanizer fixes prose. This fixes everything a repo leaks besides prose: trailers, authorship, history, branch names, config files, and comments that narrate a diff. When a commit message body needs prose work, use humanizer on the body and come back here for the mechanics.
The single most important rule: rewriting history is destructive and cannot be undone once you have deleted the backups. Read "Scope before you touch" first, every time. A repo that is merely embarrassing is recoverable. A repo whose shared history you rewrote without asking is a Monday morning outage for everyone else who cloned it.
What actually leaks
Ordered by how reliably it identifies a tool. The top group is a fingerprint. The bottom group is a guess.
Tier 1: unambiguous
- Commit trailers.
Co-Authored-By: Claude <[email protected]>,Co-Authored-By: Claude Opus 4.8 <[email protected]>,Co-authored-by: Cursor Agent,Co-authored-by: Copilot,Co-authored-by: openai-codex[bot]. - Generated-with footers in commits, PR bodies, and issue bodies:
🤖 Generated with [Claude Code](https://claude.com/claude-code),Generated with Cursor,Created by Devin. - Bot authorship. Check author and committer separately.
[email protected],[email protected],*[bot]@users.noreply.github.com,devin-ai-integration[bot]. - Branch names:
claude/*,cursor/*,codex/*,devin/*,copilot/*. - Assistant config committed by accident:
.claude/,CLAUDE.md,.cursor/,.cursorrules,.aider*,.github/copilot-instructions.md,.windsurfrules,AGENTS.md,.specstory/. - Attribution in docs: "Built with Claude Code", "This project was generated by...".
Tier 2: strong but circumstantial
- Em dashes in commit subjects. Almost nobody reaches for
—in a terminal. - Commit bodies with bolded inline headers, or
**Changes:**followed by a bulleted rule of three. - Subjects in Title Case, or subjects over ~72 chars that read like documentation.
- Emoji-prefixed subjects in a repo that has no gitmoji convention.
- A body that explains the why of something trivial at three-paragraph length.
- Suspiciously uniform commit cadence: forty commits in one hour, every message the same shape.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 274 lines · 111 tokens per session scan A 7f6ba8f3d377
de-claude is a skill published in the GitHub repository XyrusCode/ai-sync (2 stars, last pushed 2d ago), licensed MIT. It adds 111 tokens to every session and 4,835 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…