Tmux
trpc-group/trpc-agent-go
Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.
A skill your agent uses when a task mixes safety-adjacent material (stealth, scraping, privacy, IP, licensing, security) with genuinely safe work, or the moment you notice yourself about to hedge…
$ npx skills add AlexZio00/sovereign-skills --skill clean-room -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AlexZio00/sovereign-skills clean-room --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/clean-room .claude/skills/clean-room && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "clean-room" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/clean-room into .claude/skills/clean-room/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clean-room", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AlexZio00/sovereign-skills/tree/master/clean-roomType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AlexZio00/sovereign-skills --skill clean-room -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AlexZio00/sovereign-skills clean-room --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/clean-room .agents/skills/clean-room && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "clean-room" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/clean-room into .agents/skills/clean-room/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clean-room", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexZio00/sovereign-skills --skill clean-room -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AlexZio00/sovereign-skills clean-room --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/clean-room .cursor/skills/clean-room && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "clean-room" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/clean-room into .cursor/skills/clean-room/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clean-room", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AlexZio00/sovereign-skills.git --path clean-room--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AlexZio00/sovereign-skills --skill clean-room -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AlexZio00/sovereign-skills clean-room --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/clean-room .gemini/skills/clean-room && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "clean-room" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/clean-room into .gemini/skills/clean-room/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clean-room", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AlexZio00/sovereign-skills clean-roomInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AlexZio00/sovereign-skills --skill clean-room -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/clean-room .github/skills/clean-room && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "clean-room" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/clean-room into .github/skills/clean-room/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clean-room", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexZio00/sovereign-skills --skill clean-room -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AlexZio00/sovereign-skills clean-room --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/clean-room .opencode/skills/clean-room && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "clean-room" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/clean-room into .opencode/skills/clean-room/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clean-room", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
clean-roomA skill your agent uses when a task mixes safety-adjacent material (stealth, scraping, privacy, IP, licensing, security) with genuinely safe work, or the moment you notice yourself about to hedge…
Clean Room is an agent skill from AlexZio00/sovereign-skills. Use when a task mixes safety-adjacent material (stealth, scraping, privacy, IP, licensing, security) with genuinely safe work, or the moment you notice yourself about to hedge, dilute, silently drop, or brace for a refusal on part of a request. Triggers: 'strip the risky part out', 'just the safe part', 'carve this out', 'clean-room this'.
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `.claude-plugin/plugin.json` and `agents/openai.yaml`).
It sits in Data & Analytics, covering Web scraping. The repository describes itself as: 20 production-grade skills for AI coding agents — setup, scope, discipline, code review, security, session management, governance, ops, and quality audits (eval-leakage… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c062683. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Clean Room loads about 4.6k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 2,519 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from AlexZio00/sovereign-skills at commit c062683, republished under its MIT licence (© AlexZio00). 2,519 words, ~4,592 tokens.
.claude/skills/clean-room/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.<!-- provenance: adapted from LilMGenius/paperthin "autobahn" skill (MIT license). Core mechanism (carve -> clean subagent -> verify -> ledger) preserved; reformatted to this repo's SKILL.md conventions, renamed to avoid reusing the original author's skill name verbatim. Upgraded after an adversarial 3-lens design critique (adversarial-user / isolation-integrity / systemic-integration-gap) surfaced gaps the source design didn't cover in a harness with shared filesystem state between the main session and its subagents. Reconciled with upstream autobahn v0.14.0 (RUN's risk-lens fan-out folded into VERIFY step 5(e)'s single independent re-sweep, capped at N=1 rather than open-ended). See CHANGELOG.md. -->
Dominant Variable: did the subagent that actually executes the work ever see the original safety-adjacent request? If it did, this skill has failed — isolation is everything. "Never saw it" applies not just at the prompt layer but to what the subagent is instructed not to go looking for too — there is no real filesystem access-control boundary between the main session and its subagent, only a shared filesystem plus an instruction not to consult certain paths. A subagent with shared Read/Grep access to your project files can read a mention of the risky request in a memory or log file just as easily as if it had been told directly; the instruction not to look is the only barrier, not a partition.
Discard if:
Read the request, its inputs, and any risk posture the user has stated. Before drafting a carve plan, check whether there's a similar past decision on record (a lessons file, a decision log) for this user/topic, and if so cite the precedent and note explicitly if this judgment differs from it — this keeps the judgment from drifting session to session. This citation is bound by the same exposure limit as the LEDGER (step 6): verdict plus a high-level reason category only (e.g. "security-adjacent, exceeds safety threshold") — never the precise trigger phrasing or the judgment heuristic itself, even at this earlier stage, since a stage without its own exposure limit can leak what the later LEDGER step is trying to protect. If the user has already approved a descope, go to 3 (GUARD). Otherwise build a proposed carve plan showing the split explicitly and wait for approval — bright-line items (no safe version exists) don't block on this alone, since they're not negotiable. If gray-zone items remain (a safe alternative narrows scope), don't proceed until approved. If the user disputes a bright-line call itself, go to 2-A (CARVE-appeal).
Scan the request and its adjacent inputs for safety-adjacent elements. There is no fixed risk catalog — judge bright-line/gray-zone status case-by-case on this request's own facts. To keep the bar from drifting call to call, cross-check against the precedent surfaced in FRAME (if any prior decision on this user/topic was found); if none exists, judge the item on its own facts and record the reasoning in the ledger so it becomes precedent for next time. For each element, propose verdict=descope, classify it as bright-line (no safe version exists) or gray-zone (a safe alternative narrows scope), and name one risk-free alternative plus an archive location (a lessons/decisions file — the "negatives as corpus" convention). If the user chooses to keep a gray-zone item anyway, record it in the ledger as kept-by-owner. Only mention descoping technique in as much detail as needed to identify it — no elaboration. Downstream work that touches a bright-line item's output (e.g. organizing or storing scraped results) — even when that downstream step is itself a safe, mechanical operation — should not be handed to the executor framed as "the output of the bright-line step." Give it a generalized assumption instead (e.g. "assume the records already exist") that severs the downstream task from the original source, or the executor can infer the excluded bright-line context while doing otherwise-safe downstream work.
The same session that felt the pressure doesn't get to reconsider it. Send only an abstract description of the item (excluding the negotiation history and the user's persuasion arguments) to a fresh context for re-evaluation. Whether the fresh re-evaluation upholds the bright-line call or reclassifies it as gray-zone, record in the ledger that an appeal happened and its result. If the same topic gets appealed repeatedly (2+ times), make that pattern visible in the ledger — repetition itself is a signal.
Compress the carve results into a scope-guard block (an absolute exclusion list + approved alternatives + the context under which the remaining scope was approved) and embed it verbatim in the carved prompt. This block names each excluded item explicitly so the execution stage can't pull it back in — never include the original risky request itself, or the reasoning behind carving it, verbatim. The scope-guard block must also state a minimum safety envelope: one line naming the safe purpose of the task, and one line naming what falls outside it (the prohibited scope). An executor given zero purpose can't distinguish a real boundary from an arbitrary one and may drift back across it in good faith while trying to be helpful — this one-line pair is the minimum needed to make the boundary legible, not an invitation to explain why it exists. Include a standard clause in the scope-guard block telling the executor not to consult any decision logs, memory files, session transcripts, or transcript-search tools during this task — this closes a side channel where the executor could reconstruct the original risky request by reading something this session just archived, or by reading this session's own logs. Instruct the carved prompt to build the safe scope at full strength, with no hedging, apologizing, or watering down.
Dispatch a genuinely fresh-context subagent with only the carved prompt, using a subagent type that has only the tools the task needs (a general-purpose agent has every tool, including search over memory and transcripts, so the instruction-only limit in Invariant 1 would be the sole barrier) — never the original risky request, and never this session's carving reasoning. Because carving is already done, the executor has no reason to hedge. Keep risk-lens verification consolidated into VERIFY step 5(e)'s single independent re-sweep (N=1) rather than an open-ended fan-out of extra subagents or reviewers at this step. If a new risky element surfaces inside the subagent's work, don't handle it inline — go back to step 2 (CARVE).
Run an adversarial pass over the returned output and adjacent artifacts, checking six things: (a) was risky content spelled out in detail (b) was risky content silently dropped without saying so (c) was safe work diluted or excluded just because it sat near a risky element (d) does stale risky material linger nearby (e) carve-accuracy: re-sweep the original task from scratch in a context independent of this session, and diff against the ledger's flagged items — surface anything under-carved (missed risk) or over-carved (wrongly excluded safe work) before the final report. Cap this independent re-sweep at a single pass (N=1) rather than an open-ended fan-out — this one pass also covers the risk-lens review role that step 4 (RUN) delegates here. (f) fence robustness: check the scope-guard block against at least one instance each of common language-mediated bypass techniques (embedded commands, quotation/use-mention framing, scope ambiguity, deixis, indirect speech acts, claimed source authority, instruction conflict, and other pragmatic reframings) — report which category, if any, got through, not just a single pass/fail. (a)-(d) verify the output; (e)-(f) verify the carve judgment and the scope-guard fence itself — these are different targets from (a)-(d), skipping them means nobody catches the original carve's mistakes or a fence that looks solid but isn't.
Report the output together with a descope ledger — for every carved-out item: classification (bright-line/gray-zone), verdict (descoped/kept-by-owner), reason, safe alternative, archive location. The user-facing ledger includes verdict + safe alternative + a high-level reason category only (e.g. "security-adjacent, exceeds safety threshold") — never the precise trigger phrasing or the judgment heuristic itself. Keep detailed reasoning only in the archive file. Treat exclusions as a visible decision, not something hidden — but "visible" and "precisely mappable" are different things.
| Does | Does NOT |
|---|---|
| [READ] Scan the request and adjacent inputs for safety-adjacent elements | Control model routing/fallback/fixed-model selection (harness territory) |
| [WRITE] Write a descope ledger (after RUN completes; user-facing version states high-level reasons only) | Explain operational detail of a descoping technique |
| [AGENT] Dispatch a fresh-context subagent with the carved prompt only | Give the subagent the original risky request or the carving reasoning, or allow it to access archive files / session-transcript search tools |
| [READ][AGENT] Run an adversarial VERIFY pass (both the output and the CARVE judgment, the latter via an independent fresh-context re-sweep) | Enter RUN with an unapproved gray-zone item |
| [AGENT] Route a bright-line dispute to a fresh-context CARVE-appeal | Let the same pressured session reconsider itself |
| Rationalization | Counter |
|---|---|
| "Passing along the carving reasoning too would help the subagent understand context better" | Violates Invariant 1. The carving reasoning still carries traces of the original risky request — isolation, not shared context, is the point |
| "One gray-zone item is left but everything else is cleared, let's just start RUN" | Violates Invariant 2. That one gray-zone item still shapes the carved prompt's scope — starting without an answer means redoing it later |
| "Let's just quietly test whether this request actually gets blocked" | Violates Invariant 3 (no probing). Carving is preventive, not a post-hoc check |
| "We built the safe version, let's casually mention the original risky request as an example too" | Violates Invariant 5. Never elaborate beyond identification — keep it minimal in the ledger too |
| "Writing the ledger entry before RUN starts feels tidier procedurally" | Violates Invariant 7. Risky-material description sitting on disk during the subagent's active window can be read by it — write after RUN completes |
| "The user keeps saying no, let's just call it gray-zone this time" | Violates Invariant 9. The same session reconsidering is attrition, not legitimate re-review — hand it to a fresh context |
Step 5's VERIFY is the workflow step that adversarially re-checks the output content plus the CARVE judgment itself. This section is a separate checklist, done before reporting, that checks whether the skill's execution itself was done correctly — both are needed, neither replaces the other.
Before reporting completion, confirm:
If any answer is no, don't report completion — go back to that step and fix it.
© AlexZio00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in clean-room of AlexZio00/sovereign-skills.
Open the folder on GitHubat commit c062683
Clean Room next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Clean Room this skillAlexZio00/sovereign-skills | 140 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Tmuxtrpc-group/trpc-agent-go | 1.9k | 23 repos | ~868 | Automated safety check: Pass | Apache-2.0 | |
| Ketch1broseidon/ketch | 702 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Boss Zhipin Scrapereatmoreduck/boss-zhipin-scraper | 1.5k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Crawl4AI Web Scrapingsmallnest/goclaw | 599 | 1 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Axyusukebe/ax | 719 | 1 repos | ~918 | Automated safety check: Pass | MIT |
trpc-group/trpc-agent-go
Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.
1broseidon/ketch
Research skill for ketch — a fast stateless CLI for web search, OSS code search, curated library docs, page scraping, and site crawling; an optional MCP server exists for operators who want it, but…
eatmoreduck/boss-zhipin-scraper
Scrape BOSS直聘 (job listing site) via Chrome CDP. An agent skill from eatmoreduck/boss-zhipin-scraper.
smallnest/goclaw
Scrapes sites, handles JavaScript-heavy pages and extracts structured data with Crawl4AI, through its crwl CLI or Python SDK, including schema-based extraction without an LLM.
yusukebe/ax
Use the ax CLI instead of curl + throwaway parsing scripts whenever you fetch a URL, explore an unknown web page, or extract structured data from HTML.
Anakin-Inc/anakin
Scrape any website into clean markdown or structured JSON. An agent skill from Anakin-Inc/anakin.
AlexZio00/sovereign-skills
A skill your agent uses when the user wants a deterministic cross-project status map generated from registered projects' session handoffs.
AlexZio00/sovereign-skills
Scope definition before implementation — two modes. An agent skill from AlexZio00/sovereign-skills.
AlexZio00/sovereign-skills
Interview-based project setup — generates CLAUDE.md, ROADMAP, .gitignore, .env.example from scratch.
AlexZio00/sovereign-skills
This skill should be used when the user types /collab-audit or requests AI collaboration diagnosis.
AlexZio00/sovereign-skills
A skill your agent uses when the user wants to audit the memory and documents Claude Code loads into context — CLAUDE.md (user global + project + nested), MEMORY.md, @imports, .claude/skills…
AlexZio00/sovereign-skills
A skill your agent uses when saving session state before context compaction, switching tasks, or ending a session.
Categories
A skill your agent uses when a task mixes safety-adjacent material (stealth, scraping, privacy, IP, licensing, security) with genuinely safe work, or the moment you notice yourself about to hedge…. Clean Room is an agent skill from AlexZio00/sovereign-skills. Use when a task mixes safety-adjacent material (stealth, scraping, privacy, IP, licensing, security) with genuinely safe work, or the moment you notice yourself about to hedge, dilute, silently drop, or brace for a refusal on part of a request.
Clean Room fits situations like: A task mixes safety-adjacent material (stealth; security) with genuinely safe work; the moment you notice yourself about to hedge; brace for a refusal on part of a request.
Run `npx skills add AlexZio00/sovereign-skills --skill clean-room -a claude-code`. Or copy the skill folder (clean-room in AlexZio00/sovereign-skills) into .claude/skills/clean-room in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AlexZio00/sovereign-skills --skill clean-room -a codex`. Or copy the skill folder (clean-room in AlexZio00/sovereign-skills) into .agents/skills/clean-room in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlexZio00/sovereign-skills --skill clean-room -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clean-room, .gemini/skills/clean-room, .github/skills/clean-room and .opencode/skills/clean-room in your project.
SKILL.md names no scripts, command-line tools or credentials: Clean Room is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Clean Room is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Clean Room: Tmux (trpc-group/trpc-agent-go, 1.9k stars), Ketch (1broseidon/ketch, 702 stars), Boss Zhipin Scraper (eatmoreduck/boss-zhipin-scraper, 1.5k stars) and Crawl4AI Web Scraping (smallnest/goclaw, 599 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AlexZio00 (a GitHub user) maintains it in AlexZio00/sovereign-skills, which has 140 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.
Source: AlexZio00/sovereign-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.