Agent skill

Ccsn Find Simplifications

by kenryu42 in kenryu42/cc-safety-net

A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…

MITAuto-check passedSales & Support

Install Ccsn Find Simplifications

skills CLI
$ npx skills add kenryu42/cc-safety-net --skill ccsn-find-simplifications -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kenryu42/cc-safety-net ccsn-find-simplifications --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ccsn-find-simplifications .claude/skills/ccsn-find-simplifications && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ccsn-find-simplifications
GitHub stars
1.6k
Token cost
~2.9k tokens
SKILL.md length
1,476 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…

  • Working in the cc-safety-net repo to find non-obvious simplification candidates: dead
  • SKILL.md covers Start With Repo Context, Treat As Intentional By Default, What Counts As A Strong… and Survey Broadly, plus 3 more sections
  • Calls bun and git
  • Contract-exceeding surfaces in the shell parser

What it does

Ccsn Find Simplifications is an agent skill from kenryu42/cc-safety-net. Use when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell parser, analyzer, guards, secret protection, policy, rules manager, audit log, hosts, CLI, or GUI. Produces evidence-backed proposals for the maintainer, not a pile of guesses.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Sales & Support, covering Proposals and quotes. The repository describes itself as: A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports… The licence is MIT.

When your agent uses it

  • Working in the cc-safety-net repo to find non-obvious simplification candidates: dead
  • Contract-exceeding surfaces in the shell parser
  • Secret protection

Example prompts

  • “/ccsn-find-simplifications”

What it can do on your machine

Read from SKILL.md and the folder at commit 2615848. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ccsn Find Simplifications loads about 2.9k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 1,476 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kenryu42/cc-safety-net at commit 2615848, republished under its MIT licence (© kenryu42). 1,476 words, ~2,862 tokens.

Download SKILL.mdSave it as .claude/skills/ccsn-find-simplifications/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ccsn-find-simplifications
description
Use when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell parser, analyzer, guards, secret protection, policy, rules manager, audit log, hosts, CLI, or GUI. Produces evidence-backed proposals for the maintainer, not a pile of guesses.
disable-model-invocation
true

Finding CC Safety Net Simplifications

This skill turns a broad "find things to simplify" request into evidence-backed candidates that remove or collapse existing surface area. It is guidance, not a checklist: follow the code, keep judgment active, and prefer a few well-proven candidates over many thin ones.

Over-engineering is this repo's documented dominant failure mode (see Scope Discipline in AGENTS.md), so simplification proposals have a tailwind — but the same discipline applies to the proposals themselves: each one must name the concrete cost the current code carries, not just "this looks complex."

Start With Repo Context

  • Read AGENTS.md (Scope Discipline, Testing, Style Guide, Knip rules), REVIEW.md (threat model and review boundary), and SECURITY.md (the standard/strict/paranoid mode contract).
  • Read docs/residual-risk.md before judging anything in src/core/shell, src/gate/analyzer, src/gate/guards, or src/core/rules. Adjudicated bypass families are settled decisions; fixtures pinning them are load-bearing even when nothing else references them. Read docs/secret-protection-known-limitations.md before judging src/gate/secret.
  • The mode contract is the repo's central seam: standard mode blocks recognizable accidental destruction and is explicitly not bypass-proof; strict/paranoid fail closed. Complexity that exists only to chase crafted adversarial shapes in standard mode exceeds the documented contract — REVIEW.md forbids adding it, which makes any existing instance a prime simplification candidate. Conversely, fail-closed machinery in strict/paranoid is contract, not bloat.

Treat As Intentional By Default

  • Every per-host directory under src/hosts (amp, claude-code, codex, cursor, pi, and the rest). Each exists because a real host tool needs it; propose deleting one only if the user says the host is dropped. Removing an unused hook, command, or method inside one is still fair game, and so is folding duplication into the shared host machinery (src/hosts/detect, src/hosts/install, src/hosts/hook, src/hosts/templates) when no host's enforcement weakens.
  • The residual-risk registry pair (docs/residual-risk-registry.json + docs/residual-risk.md) and the strict/paranoid fail-closed fixtures that back its families.
  • The behavioral contract corpus: tests/gate/behavioral-contract-cases.ts, tests/gate/pipeline-contract-cases.ts, and the hand-edited verdict table tests/fixtures/gate/harvested-verdicts.jsonl. Per AGENTS.md, a row there is a stated expectation, not a recording; a proposal that needs a row flipped must name the row and argue the flip on contract grounds. The two snapshot surfaces (explain in tests/cli/explain, doctor --json in tests/cli/doctor) are byte contracts, not incidental output.
  • The zero-runtime-dependency posture. Hand-rolled shell parsing, JSONC/TOML reading, and atomic writes are the product, not a hand-rolling smell — this is a security hook with a deliberately minimal supply chain. Do not propose swapping the parser, a guard, or a reader in src/core/io for an npm package; a new dependency is a maintainer decision to propose separately, never a "low effort" cleanup.
  • The rules manager's resource limits (src/rules-manager/resource-limits.ts) and the parser's exhaustion budgets. SECURITY.md publishes their numbers; they are contract.
  • Adversarial-looking strings in tests are analyzer input data, never executed. Do not propose removing them as dangerous or redundant without checking which contract row or residual-risk family they pin.

What Counts As A Strong Candidate

A strong simplification removes, folds, or demotes something real, with evidence the current design costs more than it buys:

  • An internal symbol, gate pipeline stage, host adapter method, or GUI implementation surface has no production consumer. For public exports (src/entries/api.ts), configuration, policy knobs, and CLI or GUI features, require contract or deprecation evidence; repository-local absence cannot prove that external users do not depend on them.
  • Tests or comments are the only consumers, and the behavior they pin is not a mode-contract guarantee, a contract-corpus row, or a residual-risk fixture.
  • Two representations mirror the same fact (e.g. a value stored on the shell model in src/core/shell/model.ts and re-derived in the analyzer, a fact computed in src/gate/facts.ts and again in a guard, or parallel per-host code that could share one path without weakening any host's enforcement). Note that bun run check already gates textual duplication via jscpd — focus on structural duplication it cannot see.
  • Standard-mode parser or rule logic whose only justification is a deliberately crafted bypass shape: per REVIEW.md that belongs to strict/paranoid fail-closed handling or documented residual risk, not emulation code.
  • Defensive copies, freezes, re-validation, or normalization applied to values a same-process trusted caller already owns. The trust boundary here is precise: hook payloads from host tools, user config/policy files, rulebooks fetched by the rules manager, and analyzed command strings are untrusted and deserve validation; values passed between this repo's own modules ordinarily do not.
  • Speculative generality with no consumer: registries with one entry, schemas ahead of their first real user, fields whose values are forced constants, options no host or entry sets.
  • An invariant, fallback, or special-case test that exists only to protect an unused API.
  • The simplified behavior may differ slightly, but the new behavior is still reasonable, within the mode contract, and easier to explain.

Thin candidates are not enough: one typo, a single knip run, "this looks complex" without call-site proof, or anything whose removal would create a false negative for recognizable danger in standard mode.

Show full SKILL.md (678 more words)Show less

Survey Broadly

Use parallel subagents when the user asks for breadth. Give each a domain and require evidence, not guesses:

  • Shell parser and model (src/core/shell): normalization passes, node kinds, fields nothing downstream reads.
  • Analyzer and rules (src/gate/analyzer, src/core/rules): rule machinery, severity plumbing, contract-exceeding emulation.
  • Guards, secret protection, and policy (src/gate/guards, src/gate/secret, src/core/policy): backstops mirroring the same fact, config knobs nothing sets.
  • Gate pipeline and core utilities (src/gate/*.ts, src/core/*.ts, src/core/io, src/core/git, src/core/paths): intake/analysis/decision plumbing, trace and explain scaffolding, helpers with one caller.
  • Rules manager and audit log (src/rules-manager, src/audit): sync and resolver states, retention and display paths no command reaches.
  • CLI and entries (src/cli, src/entries): commands, flags, install/doctor/policy/rule flows, output formatting, entry files that re-export what nothing imports.
  • Hosts (src/hosts per-host directories and shared machinery, hooks/, the plugin manifests): per-host duplication, unused adapter methods, template branches no host takes.
  • GUI (src/gui, src/gui/frontend): surfaces or state with no interaction path.
  • Tests, scripts, build, evals (tests/, scripts/, evals/): redundant fixtures, helpers duplicating each other, verification scripts checking what another gate already checks.

Do not let the first good candidate stop the survey, and start with the largest production files — duplicated lifecycle and defensive machinery costs more than stray unused symbols.

Prove Or Reject Each Candidate

Classify consumers before writing anything up:

  • Production corpus: src/, hooks/, scripts/ used at build/publish time, the plugin manifests (.claude-plugin/plugin.json, .claude-plugin/marketplace.json, .codex-plugin/plugin.json, kimi.plugin.json), package.json bin/pi/peerDependencies wiring, and the tracked skills/ directory. Reachability runs through src/entries/*: a symbol only an entry file exports is still production if that entry is a published surface. Ignore dist/ (generated) and anything git ls-files does not list.
  • Non-production corpus: tests/ and comments. README and other docs are non-runtime evidence, but count as contract consumers for public surfaces.
  • Ambiguous corpus: tests/e2e, tests/e2e-live, and evals/ exercise real host-tool wiring — these often pin integration contracts; read them before classifying.

Use rg first: the exact symbol, config key, CLI flag, rule id, host name string, and any wire/JSON strings (hosts dispatch on string tool names, so grep strings, not just identifiers). Then read the call sites. knip helps but runs in --production mode — a /** @internal */ tag means test-only-by-design, not dead; and dynamic string dispatch hides real consumers from it.

Reject or downgrade when:

  • A production consumer exists and removal would be a feature decision, not a cleanup.
  • The surface is pinned by the mode contract, a contract-corpus row, a residual-risk family, or a documented decision in docs/, and the new evidence does not beat the recorded rationale.
  • Removal would cause a standard-mode false negative for a plausible accidental command, or weaken strict/paranoid fail-closed behavior.
  • Removal forces broad churn without reducing public surface or required behavior.

Report, Don't Restructure

This repo has no notes system and a solo maintainer. The deliverable is a report to the user, strongest evidence first. For each candidate:

  • What: the exact symbols/files to remove, fold, or demote, with file:line references.
  • Evidence: production vs test/doc consumers found, and the searches that establish absence.
  • What we give up: the strongest counterargument, stated honestly — including any behavior change and why it stays within the mode contract.
  • Blast radius: tests, docs, fixtures, contract rows, and snapshots that would change with it.

Do not create new docs, directories, dependencies, or process files to hold findings — placement of new repo structure is the maintainer's call. Do not implement removals during a survey unless the user asked for fixes; when they do, implement the smallest change per candidate, keep tests/ mirroring src/, and follow the Red–Green rule for any behavior change: the failing expectation (a contract row or stated assertion) lands first, and re-recording a snapshot or editing the verdict table is never the first step.

Validation

A findings-only survey needs no checks. When candidates are implemented, run bun run check once at the end (never its pieces separately). If knip then flags fallout, fix the root cause per the Knip section of AGENTS.md — unexport, tag /** @internal */, or trim the barrel; never touch ignoreIssues. If a change flips a verdict-table row or re-records one of the two permitted snapshots, the commit message must name which entries changed and why.

© kenryu42, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/ccsn-find-simplifications of kenryu42/cc-safety-net.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 2615848

Compare with similar skills

Ccsn Find Simplifications next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ccsn Find Simplifications compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ccsn Find Simplifications this skillkenryu42/cc-safety-net1.6k—~2.9kAutomated safety check: PassMIT
Doc Coauthoringaws-samples/sample-strands-agent-with-agentcore19540 repos~3.2kAutomated safety check: PassMIT
AI Meetingccplugins/awesome-claude-code-plugins968—~2.4kAutomated safety check: NotesApache-2.0
Exploration Modefjrevoredo/mini-diarium308—~3.4kAutomated safety check: PassMIT
Audit Onboarding Proposalhoangnb24/repository-harness1.2k—~4kAutomated safety check: PassMIT
No Negative EchoLB623/no-negative-echo897—~965Automated safety check: PassMIT

Similar skills

  • Doc Coauthoring

    aws-samples/sample-strands-agent-with-agentcore

    Official

    Guide users through a structured workflow for co-authoring documentation.

    195 GitHub starsUsed in 40 repos~3.2k tokens
    Sales & SupportAuto-check passed
  • AI Meeting

    ccplugins/awesome-claude-code-plugins

    Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.

    968 GitHub stars~2.4k tokensUpdated 1 mo ago
    Sales & SupportAuto-check: notes
  • Exploration Mode

    fjrevoredo/mini-diarium

    Enter exploration mode: a thinking partner for researching and thinking through ideas and problems before implementation.

    308 GitHub stars~3.4k tokensUpdated today
    Sales & SupportAuto-check passed
  • Audit Onboarding Proposal

    hoangnb24/repository-harness

    Use only when the user explicitly invokes $audit-onboarding-proposal.

    1.2k GitHub stars~4k tokensUpdated 4 days ago
    Sales & SupportAuto-check passed
  • No Negative Echo

    LB623/no-negative-echo

    Prevent 此地无银三百两式 residue: finalize artifacts without echoing rejected session-only alternatives into labels, metadata, commits, PRs, or handoffs.

    897 GitHub stars~965 tokensUpdated 1 mo ago
    Sales & SupportAuto-check passed
  • GEO Service Proposal Generator

    zubair-trabzada/geo-seo-claude

    Builds a client-ready AI-search-optimization proposal from an existing GEO audit, with pricing tiers, an ROI estimate and a markdown document ready to send.

    11k GitHub stars~3k tokensUpdated yesterday
    Sales & SupportAuto-check: notes

More from kenryu42/cc-safety-net

  • Release Notes

    kenryu42/cc-safety-net

    Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.

    1.6k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Verify Cc Safety Net

    kenryu42/cc-safety-net

    Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

    1.6k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Cc Safety Net

    kenryu42/cc-safety-net

    Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.

    1.6k GitHub stars~4.4k tokensUpdated today
    Auto-check: notes
  • Ccsn No Comments

    kenryu42/cc-safety-net

    Use in the cc-safety-net repo when bun run lint:comments or bun run check reports a comment, a stale comment-allowlist entry, or a file it cannot parse, and before writing a code comment there.

    1.6k GitHub stars~907 tokensUpdated today
    Auto-check passed

Questions about Ccsn Find Simplifications

What does Ccsn Find Simplifications do?

A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…. Ccsn Find Simplifications is an agent skill from kenryu42/cc-safety-net. Use when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell parser, analyzer, guards, secret protection, policy, rules manager, audit log, hosts, CLI, or GUI.

When should I use Ccsn Find Simplifications?

Ccsn Find Simplifications fits situations like: working in the cc-safety-net repo to find non-obvious simplification candidates: dead; contract-exceeding surfaces in the shell parser; secret protection.

How do I install Ccsn Find Simplifications in Claude Code?

Run `npx skills add kenryu42/cc-safety-net --skill ccsn-find-simplifications -a claude-code`. Or copy the skill folder (.agents/skills/ccsn-find-simplifications in kenryu42/cc-safety-net) into .claude/skills/ccsn-find-simplifications in your project. Claude Code loads it when a task matches its description.

How do I install Ccsn Find Simplifications in Codex?

Run `npx skills add kenryu42/cc-safety-net --skill ccsn-find-simplifications -a codex`. Or copy the skill folder (.agents/skills/ccsn-find-simplifications in kenryu42/cc-safety-net) into .agents/skills/ccsn-find-simplifications in your project. Codex loads it when a task matches its description.

Can I use Ccsn Find Simplifications in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kenryu42/cc-safety-net --skill ccsn-find-simplifications -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ccsn-find-simplifications, .gemini/skills/ccsn-find-simplifications, .github/skills/ccsn-find-simplifications and .opencode/skills/ccsn-find-simplifications in your project.

What does Ccsn Find Simplifications need to run?

Going by SKILL.md and its folder, Ccsn Find Simplifications needs the command-line tools its instructions call (bun and git).

Does Ccsn Find Simplifications access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ccsn Find Simplifications safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ccsn Find Simplifications use?

Ccsn Find Simplifications is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ccsn Find Simplifications use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ccsn Find Simplifications?

Skills that share tags, products or a category with Ccsn Find Simplifications: Doc Coauthoring (aws-samples/sample-strands-agent-with-agentcore, 195 stars), AI Meeting (ccplugins/awesome-claude-code-plugins, 968 stars), Exploration Mode (fjrevoredo/mini-diarium, 308 stars) and Audit Onboarding Proposal (hoangnb24/repository-harness, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ccsn Find Simplifications?

kenryu42 (a GitHub user) maintains it in kenryu42/cc-safety-net, which has 1,582 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.

Source: kenryu42/cc-safety-net on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.