Agent skill

Janitor Discover

by khendzel in khendzel/skills-janitor

Find new skills on GitHub or check a specific skill before installing.

MITAuto-check passedSecurity

Install Janitor Discover

skills CLI
$ npx skills add khendzel/skills-janitor --skill janitor-discover -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install khendzel/skills-janitor janitor-discover --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/khendzel/skills-janitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/janitor-discover .claude/skills/janitor-discover && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
janitor-discover
GitHub stars
123
Token cost
~1.6k tokens
SKILL.md length
728 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Find new skills on GitHub or check a specific skill before installing.

  • Works in 2 steps: Dispatch on argument shape → Present results per mode
  • The user wants to search for skills
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls bash; reaches github.com; needs GITHUB_TOKEN

What it does

Janitor Discover is an agent skill from khendzel/skills-janitor. Find new skills on GitHub or check a specific skill before installing. Use when the user wants to search for skills, evaluate a skill URL, check overlap and security risk before installing, or compare a local skill against alternatives. Trigger with '/janitor-discover'.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Requires bash 3.2+, curl, and network access to the GitHub API (anonymous works; GITHUBTOKEN raises rate limits).

It sits in Security. It works with GitHub and n8n. The repository describes itself as: Tinder for your Claude Code skills, subagents and MCP servers. Swipe away what wastes context, scan for prompt injection, get honest token costs. Fixes what it finds and actually… The licence is MIT.

When your agent uses it

  • The user wants to search for skills
  • Evaluate a skill URL
  • Check overlap and security risk before installing
  • Compare a local skill against alternatives

Example prompts

  • “/janitor-discover”
  • “/janitor-discover”

Requirements

  • A credential in GITHUB_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code. Requires bash 3.2+, curl, and network access to the GitHub API (anonymous works; GITHUB_TOKEN raises rate limits).
  • Pre-approved tools (allowed-tools): Read, Bash(bash:*)

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Dispatch on argument shape
  2. Present results per mode

What it can do on your machine

Read from SKILL.md and the folder at commit 4b42f39. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(bash:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code. Requires bash 3.2+, curl, and network access to the GitHub API (anonymous works; GITHUB_TOKEN raises rate limits).

    From compatibility in the SKILL.md frontmatter.

Context cost

Janitor Discover loads about 1.6k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 728 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from khendzel/skills-janitor at commit 4b42f39, republished under its MIT licence (© khendzel). 728 words, ~1,647 tokens.

Download SKILL.mdSave it as .claude/skills/janitor-discover/SKILL.md (or your agent's skills folder).
name
janitor-discover
description
Find new skills on GitHub or check a specific skill before installing. Use when the user wants to search for skills, evaluate a skill URL, check overlap and security risk before installing, or compare a local skill against alternatives. Trigger with '/janitor-discover'.
allowed-tools
Read, Bash(bash:*)
compatibility
Designed for Claude Code. Requires bash 3.2+, curl, and network access to the GitHub API (anonymous works; GITHUB_TOKEN raises rate limits).
argument-hint
<query-or-url> [--limit N] [--compare <skill>] [--json]
version
1.6.0
author
Krzysztof Hendzel <krzysztoff.hendzel@gmail.com>
license
MIT
tags
skills, discovery, github-search, pre-install, duplicates, security

Skill Discovery & Pre-Install Check

Combined entry point for finding skills on GitHub and for evaluating a specific skill (URL or local path) before installing it.

Overview

Replaces the v1.2 split between /janitor-search and /janitor-precheck. The dispatcher picks the right mode from the argument shape. Search results are relevance-gated (a repo must carry a skill signal in its name/description/topics) and ranked by relevance before stars, so generic mega-repos don't crowd out actual skills.

ArgumentModeWhat runs
Keyword(s) like seo or n8n workflowsDiscoverysearch.sh — find matching skills on GitHub
--compare <skill-name>Comparisonsearch.sh --compare — find alternatives to a local skill
Full URL: https://github.com/user/skillPre-install checkprecheck.sh — analyze before installing
Short repo: user/skillPre-install checkprecheck.sh (auto-expanded to URL)
Local path: ~/path/to/skillPre-install checkprecheck.sh (local folder)

Pre-install mode runs two checks, not one: overlap against what's already installed, and (since v1.6) a security scan of the candidate via security.sh — the same heuristics /janitor-security uses on installed skills.

Prerequisites

  • Claude Code with the skills-janitor plugin installed (provides scripts/discover.sh, search.sh, precheck.sh, compare.sh)
  • bash 3.2+ and curl
  • Network access to api.github.com (anonymous OK; set GITHUB_TOKEN for higher rate limits and code search)

Instructions

Step 1: Dispatch on argument shape
bash
bash ~/.claude/skills/skills-janitor/scripts/discover.sh <query-or-url> [options]

Examples:

  • discover.sh seo — search for SEO-related skills
  • discover.sh n8n --limit 20 — top 20 n8n skills
  • discover.sh --compare marketing-seo-audit — alternatives to a local skill
  • discover.sh https://github.com/user/my-skill — check before installing
  • discover.sh user/my-skill — same, short form
Step 2: Present results per mode

Discovery mode — ranked list of GitHub repos with skill name, description, stars, last updated, and a one-line verdict.

Pre-install mode — two sections. First, overlap analysis: which of the user's existing skills (including plugin skills) overlap with the candidate by description, and a recommendation to install / skip / replace. Second, a --- Security (<scope>) --- block.

Always report the security scope back to the user, because it differs by source:

SourceScanned
Local pathFull directory — SKILL.md and bundled scripts
URL / user/repoFetched SKILL.md only — scripts are never downloaded, so re-check after cloning

A PASS on a remote URL therefore means "nothing suspicious in the text we could see", not "this repo is safe". Say so when the candidate ships scripts.

Output

Discovery: a numbered table (repository, stars, updated, INSTALLED/AVAILABLE status).

Pre-install: overlap buckets (HIGH ≥60%, MODERATE 30–59%, LOW <30%) with shared keywords and a final verdict line (HIGH_OVERLAP / MODERATE_OVERLAP / SAFE), plus a security block that prints either No suspicious patterns found. (PASS), Security scan unavailable. (UNKNOWN), or VERDICT: REVIEW|RISK followed by one severity + title + evidence line per finding. With --json, the same data lands under a security key (verdict, scope, findings).

Show full SKILL.md (305 more words)Show less

Error Handling

  1. Error: GitHub API rate limit exceeded Solution: Set the GITHUB_TOKEN environment variable (any classic token, no scopes needed) and re-run; anonymous search allows only a few requests per minute.

  2. Error: Could not fetch SKILL.md from <url> Solution: The repo keeps its SKILL.md at a non-standard path — pass a direct URL to the SKILL.md file, or a local clone path instead.

  3. Error: No results for a valid topic Solution: The relevance gate drops repos without any skill signal. Broaden the keyword (e.g. n8n skill → n8n) or check the cached results note — results are cached for 24h in data/search-cache.json.

  4. Error: Security scan unavailable. (verdict UNKNOWN) Solution: security.sh failed or returned no parseable JSON — the overlap result is still valid, but do not present the candidate as security-checked. Re-run, or scan after cloning with /janitor-security.

Examples

Example 1: Find skills by topic

Input: "Find me an n8n skill."

Output: Run discover.sh n8n, present the ranked table, and flag any result already installed.

Example 2: Check before installing

Input: "Is github.com/user/seo-helper worth installing?"

Output: Run discover.sh https://github.com/user/seo-helper, then summarize: overlap with existing skills, the verdict (e.g. "MODERATE_OVERLAP — 45% with marketing-skills:seo-audit"), the security verdict, and a recommendation. Note that only the fetched SKILL.md was scanned.

Example 3: Candidate trips the security scan

Input: "Check user/handy-helper before I install it."

Output: Run discover.sh user/handy-helper. If the security block reports VERDICT: RISK, lead with that rather than the overlap number — quote the finding's severity, title and evidence, explain that RISK means "read this before trusting it" (not "malware"), and remind the user that bundled scripts were not fetched.

Resources

  • Dispatcher (plugin-relative): {baseDir}/../../scripts/discover.sh
  • Search cache: data/search-cache.json (24h TTL)
  • /janitor-security — same scan, run across everything already installed
  • /janitor-report — health check of currently installed skills
  • /janitor-value — are existing skills earning their context cost
  • /janitor-fix — fix issues with installed skills

© khendzel, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/janitor-discover of khendzel/skills-janitor.

Open the folder on GitHubat commit 4b42f39

Compare with similar skills

Janitor Discover next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Janitor Discover compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Janitor Discover this skillkhendzel/skills-janitor123—~1.6kAutomated safety check: PassMIT
ReleaseZeecka/AperiSolve852—~1.9kAutomated safety check: PassMIT
Triage Codeqlnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0
Security AdvisoryMidnightBSD/src114—~2.2kAutomated safety check: PassCustom licence
Security Vulnerability Analysiseclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Release

    Zeecka/AperiSolve

    Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag.

    852 GitHub stars~1.9k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Advisory

    MidnightBSD/src

    Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

    114 GitHub stars~2.2k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Vulnerability Analysis

    eclipse-ankaios/ankaios

    Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

    125 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

    143 GitHub stars~1.1k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from khendzel/skills-janitor

  • Janitor Fix

    khendzel/skills-janitor

    Automatically fix skill problems (safe preview first). An agent skill from khendzel/skills-janitor.

    123 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Janitor Report

    khendzel/skills-janitor

    Full health check of all your skills in one report. An agent skill from khendzel/skills-janitor.

    123 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Janitor Swipe

    khendzel/skills-janitor

    Tinder for your Claude Code skills. An agent skill from khendzel/skills-janitor.

    123 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Janitor Value

    khendzel/skills-janitor

    Show whether each skill is earning its context-window cost — combined tokens-used view sorted by waste.

    123 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Works with

Categories

Questions about Janitor Discover

What does Janitor Discover do?

Find new skills on GitHub or check a specific skill before installing. Janitor Discover is an agent skill from khendzel/skills-janitor. Find new skills on GitHub or check a specific skill before installing.

When should I use Janitor Discover?

Janitor Discover fits situations like: the user wants to search for skills; evaluate a skill URL; check overlap and security risk before installing; compare a local skill against alternatives.

How do I install Janitor Discover in Claude Code?

Run `npx skills add khendzel/skills-janitor --skill janitor-discover -a claude-code`. Or copy the skill folder (skills/janitor-discover in khendzel/skills-janitor) into .claude/skills/janitor-discover in your project. Claude Code loads it when a task matches its description.

How do I install Janitor Discover in Codex?

Run `npx skills add khendzel/skills-janitor --skill janitor-discover -a codex`. Or copy the skill folder (skills/janitor-discover in khendzel/skills-janitor) into .agents/skills/janitor-discover in your project. Codex loads it when a task matches its description.

Can I use Janitor Discover in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add khendzel/skills-janitor --skill janitor-discover -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/janitor-discover, .gemini/skills/janitor-discover, .github/skills/janitor-discover and .opencode/skills/janitor-discover in your project.

What does Janitor Discover need to run?

Going by SKILL.md and its folder, Janitor Discover needs the command-line tools its instructions call (bash) and credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN. Its frontmatter pre-approves these tools: Read, Bash(bash:*). Compatibility (from SKILL.md): Designed for Claude Code. Requires bash 3.2+, curl, and network access to the GitHub API (anonymous works; GITHUB_TOKEN raises rate limits)..

Does Janitor Discover access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Janitor Discover safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Janitor Discover use?

Janitor Discover is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Janitor Discover use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Janitor Discover?

Skills that share tags, products or a category with Janitor Discover: Release (Zeecka/AperiSolve, 852 stars), Triage Codeql (netdata/netdata, 81k stars), Security Advisory (MidnightBSD/src, 114 stars) and Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Janitor Discover?

khendzel (a GitHub user) maintains it in khendzel/skills-janitor, which has 123 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 30, 2026.

Source: khendzel/skills-janitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.