Skills Janitor

Tinder for your Claude Code skills. Swipe through your collection and delete what's wasting context, in seconds.

Works with Claude Code and OpenAI Codex. 6 commands, zero dependencies.

/janitor-swipe — swipe keep / delete / skip through every installed skill

New in v1.4: /janitor-swipe. Every installed skill becomes a card, sorted heaviest-and-least-used first. Swipe left to delete, right to keep, down to skip. Most setups clear 30–40% of their skill token cost before the deck even ends. Jump to swipe →

Scans every place a skill lives: user, project, codex, and every skill installed via /plugin install — plus your subagents and MCP servers. Surfaces duplicates, broken symlinks, unused skills, and connected-but-never-called MCP servers cluttering your context. Usage counts come from real session transcripts, including skills Claude auto-triggered.

Commands

Command What it does
/janitor-report Health check: inventory, duplicates, broken skills. --brief for inventory only.
/janitor-fix Auto-fix issues. --prune removes broken symlinks and empty dirs.
/janitor-value Honest token costs (always-loaded descriptions vs on-demand bodies) + usage, skills and subagents.
/janitor-security Heuristic scan for prompt injection, hidden instructions, and dangerous script patterns. (v1.6+)
/janitor-discover Search GitHub for skills, or check a URL before installing — now including a pre-install security scan.
/janitor-swipe Interactive TUI — swipe keep/delete/skip through skills AND MCP servers, sorted most-likely-waste first. (v1.4+)

Each has its own slash command. Or use natural language: "check my skills", "which skills are wasting context?", "find an n8n skill".

Install

/plugin marketplace add khendzel/skills-janitor
/plugin install skills-janitor

Or via skills.sh:

npx skills add khendzel/skills-janitor

Or clone directly:

git clone https://github.com/khendzel/skills-janitor ~/.claude/skills/skills-janitor

Security scan (v1.6)

A skill is text your agent trusts. Public research found prompt injection in roughly a third of tested community skills — so the janitor now scans for the known bad shapes: instruction-override phrases, "don't tell the user" directives, instructions hidden in HTML comments or zero-width unicode, smuggled base64 payloads, and scripts that pipe the network into a shell or read credential stores.

/janitor-security          # audit everything installed
/janitor-discover <url>    # overlap + security check BEFORE installing

Verdicts are honest heuristics (PASS / REVIEW / RISK): a RISK means "read this before trusting it", not "malware". Calibrated for low noise — on a real 178-skill machine it flags 2, both genuinely worth reading.

Swipe through your skills (v1.4)

Tinder-style triage for your skill collection. The deck is sorted heaviest-and-least-used first, so most users hit ← delete through the top 5–10 cards and quit before reviewing everything.

!bash ~/.claude/skills/skills-janitor/scripts/swipe.sh

(The ! prefix runs in your terminal, not the Claude Code Bash tool — the TUI needs a real interactive stdin.)

Controls: delete, keep, skip, u undo, i inspect full description, q quit.

Plugin skills are flagged for review (you can't rm individual plugin skills — they belong to a plugin). User-scope skills stage for actual deletion, applied on y confirmation at the end.

What v1.3 catches that v1.2 missed

The duplicate detector now flags cross-scope overlaps that were invisible before:

=== Skills Janitor - Duplicate Detection ===

--- Description Overlap (Jaccard > 30%) ---

  [98%] marketing-seo-audit <-> marketing-skills:seo-audit
        Scopes: user / plugin

  [100%] marketing-content-strategy <-> marketing-skills:content-strategy
        Scopes: user / plugin

If you installed a plugin that re-implements a skill you already had standalone, v1.3 tells you. v1.2 couldn't, because it was blind to the plugin tree entirely.

v1.2 → v1.3 migration

The five v1.2 aliases were removed in v1.5. Renames:

v1.2 v1.3
/janitor-audit /janitor-report --brief
/janitor-usage /janitor-value
/janitor-tokens /janitor-value
/janitor-search /janitor-discover
/janitor-precheck /janitor-discover <url>

Full release notes: CHANGELOG.md.

Requirements

Bash, Python 3, curl. No pip installs, no node modules.

Contributing

PRs welcome. Each command is self-contained in skills/janitor-*/SKILL.md plus a sibling script in scripts/.

License

MIT