Front door for running the clean-room unattended loop as a Claude Code dynamic WORKFLOW using in-session subagents, so it never spends claude -p API tokens.

Apache-2.0Auto-check passedSecurity

Install Clean Room Loop

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill clean-room-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins clean-room-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/whit3rabbit/clean-room-skill/skills/clean-room-loop .claude/skills/clean-room-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clean-room-loop
GitHub stars
1.2k
Token cost
~1.7k tokens
SKILL.md length
673 words
Files
1
Skills in repo
686
Repo updated
First seen
Licence
Apache-2.0

At a glance

Front door for running the clean-room unattended loop as a Claude Code dynamic WORKFLOW using in-session subagents, so it never spends claude -p API tokens.

  • Works in 5 steps: Get the brief. Take the end goal from… → Run the discussion. Collect the fields… → Ensure the workflow is installed… → …
  • Says clean-room as a workflow
  • SKILL.md covers What this is (and is NOT) and Steps
  • Calls claude and npx

What it does

Clean Room Loop is an agent skill from hashgraph-online/awesome-codex-plugins. Front door for running the clean-room unattended loop as a Claude Code dynamic WORKFLOW using in-session subagents, so it never spends claude -p API tokens. Use when the user wants to run a clean-room / reverse-engineering / source-to-clean-implementation task hands-off but without paying per-token for clean-room-skill run, or says "clean-room as a workflow", "unattended clean-room without API cost", "/clean-room-loop". Runs a short discussion (authorization, end goal, target stack, policies, source roots, output…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware and Subagents. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Says clean-room as a workflow
  • Unattended clean-room without API cost
  • /clean-room-loop

Example prompts

  • “clean-room as a workflow”
  • “unattended clean-room without API cost”
  • “/clean-room-loop”
  • “/clean-room-loop”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Get the brief. Take the end goal from the invocation if present. If missing, ask what they are
  2. Run the discussion. Collect the fields below with AskUserQuestion (batch - max 4 per call,
  3. Ensure the workflow is installed project-local, preview, STOP for confirmation, then launch.
  4. Fallback. If Workflow() errors or is unavailable (non-Claude host, or dynamic workflows
  5. Hand back the workflow's result (the terminal clean-room-result.json result string, task

What it can do on your machine

Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clean Room Loop loads about 1.7k tokens when it runs. Until then it costs about 177 tokens; SKILL.md has 673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~177
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its Apache-2.0 licence (© hashgraph-online). 673 words, ~1,704 tokens.

Download SKILL.mdSave it as .claude/skills/clean-room-loop/SKILL.md (or your agent's skills folder).
name
clean-room-loop
description
Front door for running the clean-room unattended loop as a Claude Code dynamic WORKFLOW using in-session subagents, so it never spends `claude -p` API tokens. Use when the user wants to run a clean-room / reverse-engineering / source-to-clean-implementation task hands-off but without paying per-token for `clean-room-skill run`, or says "clean-room as a workflow", "unattended clean-room without API cost", "/clean-room-loop". Runs a short discussion (authorization, end goal, target stack, policies, source roots, output roots, iterations) then launches the `clean-room-loop` workflow with the answers. NOT the enforced OS-level wall - that is `clean-room-skill run --agent-runtime claude`.
argument-hint
end goal, authorized source roots, target stack, output roots, optional max iterations

Clean-room loop (discussion -> clean-room-loop workflow launch)

Conversational front door to the clean-room-loop dynamic workflow (.claude/workflows/clean-room-loop.js). The workflow runs in the background with no way to ask anything mid-run, so the discussion happens HERE; answers pass as args.

Claude Code only. Dynamic workflows are a Claude Code feature. In Pi/Codex/OpenCode the Workflow() call will not exist - see the Fallback step. Only this workflow shortcut is Claude Code specific; the underlying clean-room skills (/clean-room:unattended, clean-room-skill run) work on every supported runtime.

Installed project-local. The workflow script ships to project-local .claude/workflows/ (not global). Workflow({ name }) discovers it from the current project's .claude/workflows/ (or ~/.claude/workflows/ if a personal copy exists). If the current project does not have it, initialize a project-local install before launching - see Step 3.

What this is (and is NOT)

  • It drives the six clean-room roles with the workflow's OWN agent() subagents (in-session, subscription, no claude -p), gating every wall crossing with the real clean-room-skill artifact validate --role leakage + schema hooks.
  • It is a cost-free path with context-level separation, NOT the OS-enforced wall. A workflow cannot set CLEAN_ROOM_* env or install hooks, so nothing stops a clean subagent from reading source off disk except the neutral-artifact discipline + the leakage gate. If the user needs the enforced boundary, use clean-room-skill run --agent-runtime claude instead (that path costs API tokens by design).
  • The workflow READS the authorized source and WRITES clean specs, plans, code, and reports under the external artifact roots. Confirm authorization and paths before launching.

Steps

  1. Get the brief. Take the end goal from the invocation if present. If missing, ask what they are reimplementing and why they are authorized to.

  2. Run the discussion. Collect the fields below with AskUserQuestion (batch - max 4 per call, ~3 calls); ask free-text ones plainly. Offer defaults so a terse brief is still runnable. Do NOT infer the end goal or target stack from source - clean-room forbids it; if unknown, ask.

    Batch A (goal + stack):

    • endGoal (free-text): what the clean implementation must do; its success definition.
    • targetStack: language / runtime / framework / packageManager / testFramework. Pass as a nested object.
    • compatibilityPolicy: public-behavior-and-API-names only (default) or public-behavior-only. Private structure/comments/internal names are NEVER mirrored.
    • featurePolicy (skippable): features to preserve / remove / add / non-goals.

    Batch B (policy):

    • licensePolicy: destination license + any blocked dep licenses.
    • dependencyPolicy: allow new deps? prefer stdlib? require approval for native deps.
    • codeHygienePolicy (skippable): max lines per code/test file, max files per iteration.
    • schemaProfile: speckit-feature-folder (default) / openspec-delta / gsd-planning-package / kiro-spec-folder.

    Batch C (roots + bounds - all safety-relevant):

    • sourceRoots (REQUIRED): absolute path(s) to the authorized source. No source = cannot run.
    • artifactBase: where run artifacts live (default ~/Documents/CleanRoom). Must be OUTSIDE the source tree and neutral-named.
    • project / taskId (skippable): neutral names; the CLI generates neutral ones if omitted.
    • maxIterations: finite inner-loop cap (default 3).
  3. Ensure the workflow is installed project-local, preview, STOP for confirmation, then launch. First confirm this project has the workflow. Dynamic workflows load from project-local .claude/workflows/. If .claude/workflows/clean-room-loop.js is absent in the current project (and no ~/.claude/workflows/clean-room-loop.js personal copy exists), initialize a project-local install before launching:

    bash
    clean-room-skill --claude --local --yes
    # or, without a global CLI:
    npx clean-room-skill@latest --claude --local --yes

    That writes clean-room-loop.js into the current project's .claude/workflows/ so Workflow({ name }) can discover it. Then show a compact preview of the args (at least endGoal, sourceRoots, artifactBase, targetStack, maxIterations) so a wrong source path or output root is caught BEFORE a filesystem-writing, source-reading run starts. STOP and wait for an explicit "yes". Do NOT call Workflow in the same turn as the preview. Only after the user confirms:

    Workflow({ name: "clean-room-loop", args: {
      endGoal,
      targetStack,                 // { language, runtime, framework, packageManager, testFramework }
      compatibilityPolicy, featurePolicy,
      licensePolicy, dependencyPolicy, codeHygienePolicy,
      sourceRoots,                 // array of absolute paths (REQUIRED)
      artifactBase, project, taskId,
      schemaProfile, maxIterations,
      specSliceRef,                // optional
    }})

    Pass only what was gathered; omit the rest (the workflow defaults them).

  4. Fallback. If Workflow() errors or is unavailable (non-Claude host, or dynamic workflows disabled), do NOT hand-run the roles here. Route the user to /clean-room:unattended, which prefers fresh-context in-harness roles on that harness and drops to the durable runner only as a last resort: clean-room-skill run --agent-commands <adapter> on Codex/Pi/other runtimes (spawns the harness CLI, shell: false), or --agent-runtime claude (spawns claude -p, Claude only, per-token) last. Use the runner only once a runner-ready manifest with loop_context exists.

  5. Hand back the workflow's result (the terminal clean-room-result.json result string, task root, and clean/implementation roots).

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/whit3rabbit/clean-room-skill/skills/clean-room-loop of hashgraph-online/awesome-codex-plugins.

Open the folder on GitHubat commit 78497e5

Compare with similar skills

Clean Room Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clean Room Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clean Room Loop this skillhashgraph-online/awesome-codex-plugins1.2k—~1.7kAutomated safety check: PassApache-2.0
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill936—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    936 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 686 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Manuscript Engagement Analytics

    hashgraph-online/awesome-codex-plugins

    Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…

    1.2k GitHub stars~875 tokensUpdated today
    Auto-check passed

Categories

Questions about Clean Room Loop

What does Clean Room Loop do?

Front door for running the clean-room unattended loop as a Claude Code dynamic WORKFLOW using in-session subagents, so it never spends claude -p API tokens. Clean Room Loop is an agent skill from hashgraph-online/awesome-codex-plugins. Front door for running the clean-room unattended loop as a Claude Code dynamic WORKFLOW using in-session subagents, so it never spends claude -p API tokens.

When should I use Clean Room Loop?

Clean Room Loop fits situations like: says clean-room as a workflow; unattended clean-room without API cost; /clean-room-loop.

How do I install Clean Room Loop in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill clean-room-loop -a claude-code`. Or copy the skill folder (plugins/whit3rabbit/clean-room-skill/skills/clean-room-loop in hashgraph-online/awesome-codex-plugins) into .claude/skills/clean-room-loop in your project. Claude Code loads it when a task matches its description.

How do I install Clean Room Loop in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill clean-room-loop -a codex`. Or copy the skill folder (plugins/whit3rabbit/clean-room-skill/skills/clean-room-loop in hashgraph-online/awesome-codex-plugins) into .agents/skills/clean-room-loop in your project. Codex loads it when a task matches its description.

Can I use Clean Room Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill clean-room-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clean-room-loop, .gemini/skills/clean-room-loop, .github/skills/clean-room-loop and .opencode/skills/clean-room-loop in your project.

What does Clean Room Loop need to run?

Going by SKILL.md and its folder, Clean Room Loop needs the command-line tools its instructions call (claude and npx). Our summary lists: Node.js.

Does Clean Room Loop access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Clean Room Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clean Room Loop use?

Clean Room Loop is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clean Room Loop use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clean Room Loop?

Skills that share tags, products or a category with Clean Room Loop: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clean Room Loop?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.