Agent skill

Clean Code

by xenitV1 in xenitV1/claude-code-maestro

The Foundation Skill. An agent skill from xenitV1/claude-code-maestro.

MITAuto-check passedDevelopment

Install Clean Code

skills CLI
$ npx skills add xenitV1/claude-code-maestro --skill clean-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xenitV1/claude-code-maestro clean-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xenitV1/claude-code-maestro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/clean-code .claude/skills/clean-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clean-code
GitHub stars
229
Token cost
~1.5k tokens
SKILL.md length
588 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

The Foundation Skill. An agent skill from xenitV1/claude-code-maestro.

  • Works in 4 steps: Verify before import - npm search or pip… → Prefer battle-tested - lodash, date-fns,… → Check npm audit / pip-audit before… → …
  • ALL code output - prevents hallucinations
  • SKILL.md covers 🚨 IRON LAWS, 📦 PROTOCOL 1: SUPPLY CHAIN…, 🔐 PROTOCOL 2: SECURITY-FIRST… and 🏗️ PROTOCOL 3: NO LAZY…, plus 6 more sections
  • Calls npm and pip

What it does

Clean Code is an agent skill from xenitV1/claude-code-maestro. The Foundation Skill. LLM Firewall + 2025 Security + Cross-Skill Coordination. Use for ALL code output - prevents hallucinations, enforces security, ensures quality.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality. The licence is MIT.

When your agent uses it

  • ALL code output - prevents hallucinations
  • Enforces security
  • Ensures quality

Example prompts

  • “/clean-code”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Verify before import - npm search or pip show for unfamiliar packages
  2. Prefer battle-tested - lodash, date-fns, zod over obscure alternatives
  3. Check npm audit / pip-audit before adding new dependencies
  4. Pin versions in production - no ^ or ~ for critical deps

What it can do on your machine

Read from SKILL.md and the folder at commit 924315b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clean Code loads about 1.5k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 588 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xenitV1/claude-code-maestro at commit 924315b, republished under its MIT licence (© xenitV1). 588 words, ~1,498 tokens.

Download SKILL.mdSave it as .claude/skills/clean-code/SKILL.md (or your agent's skills folder).
name
clean-code
description
The Foundation Skill. LLM Firewall + 2025 Security + Cross-Skill Coordination. Use for ALL code output - prevents hallucinations, enforces security, ensures quality.

<domain_overview>

🛡️ CLEAN CODE: THE FOUNDATION

Philosophy: This skill is the FOUNDATION - it applies to ALL other skills. Every piece of code must pass these gates. ALGORITHMIC ELEGANCE MANDATE (CRITICAL): Never prioritize "clever" code over readable, intent-revealing engineering. AI-generated code often fails by introducing unnecessary abstractions or using vague naming conventions that obscure logic. You MUST use intent-revealing names for every variable and function. Any implementation that increases cognitive complexity without a proportional gain in performance or scalability must be rejected. Avoid "Hype-Driven Development"—proven patterns trump trending but unstable frameworks. </domain_overview> <iron_laws>

🚨 IRON LAWS

1. NO HALLUCINATED PACKAGES - Verify before import
2. NO LAZY PLACEHOLDERS - Code must be runnable
3. NO SECURITY SHORTCUTS - Production-ready defaults
4. NO OVER-ENGINEERING - Simplest solution first

</iron_laws> <security_protocols>

📦 PROTOCOL 1: SUPPLY CHAIN SECURITY

LLMs hallucinate packages that sound real but don't exist.

  1. Verify before import - npm search or pip show for unfamiliar packages
  2. Prefer battle-tested - lodash, date-fns, zod over obscure alternatives
  3. Check npm audit / pip-audit before adding new dependencies
  4. Pin versions in production - no ^ or ~ for critical deps 2025 AI Package Risks:
  • Never import AI "wrapper" libraries without verification
  • LLM SDKs: Use official only (openai, anthropic, google-generativeai)
  • Vector DBs: Stick to established (pinecone, weaviate, chromadb)

🔐 PROTOCOL 2: SECURITY-FIRST DEFAULTS

Frontend Security:

ForbiddenRequired
dangerouslySetInnerHTMLDOMPurify sanitization
Inline event handlersEvent delegation
eval(), new Function()Static code only
Storing tokens in localStoragehttpOnly cookies
Backend Security:
ForbiddenRequired
---------------------
CORS: *Explicit origin whitelist
Raw SQL stringsParameterized queries
chmod 777Principle of least privilege
Hardcoded secretsEnvironment variables + validation
API Security (2025):
  • Rate limiting on ALL public endpoints
  • Input validation at the gate (Zod/Pydantic)
  • Output sanitization for AI-generated content
  • PASETO > JWT for new projects </security_protocols> <modularity_and_placeholder_rules>

🏗️ PROTOCOL 3: NO LAZY PLACEHOLDERS

Forbidden Patterns:

javascript
// ❌ BANNED
// TODO: Implement this
// ... logic goes here
function placeholder() { }
throw new Error('Not implemented');

Required:

  • Every function must be runnable
  • If too complex, break into smaller complete functions
  • "Hurry" is not an excuse - write minimal viable implementation

📐 PROTOCOL 4: MODULARITY & STRUCTURE

The 50/300 Rule:

  • Functions > 50 lines → Break down
  • Files > 300 lines → Split into modules SOLID Principles:
    PrincipleQuick Check
    Single ResponsibilityDoes this do ONE thing?
    Open/ClosedCan I extend without modifying?
    Liskov SubstitutionCan subtypes replace parent?
    Interface SegregationAre interfaces minimal?
    Dependency InversionDo I depend on abstractions?
    </modularity_and_placeholder_rules>
    <complexity_and_dependencies>
Show full SKILL.md (247 more words)Show less

🎯 PROTOCOL 5: COMPLEXITY CAP

Native First:

javascript
// ❌ Don't install is-odd
npm install is-odd
// ✅ Use native
const isOdd = n => n % 2 !== 0;

Anti-Patterns:

  • AbstractFactoryBuilderManager for simple functions
  • 10 layers of abstraction for CRUD
  • "Future-proofing" for requirements that don't exist YAGNI: You Aren't Gonna Need It. Build for today's requirements.

🔄 PROTOCOL 6: DEPENDENCY HYGIENE

Freshness Check:

bash
npm outdated      # Check for updates
npm audit         # Check for vulnerabilities

The CVE Brake:

  • "Latest" is not always "Safest"
  • If latest has Critical CVE → Rollback to last secure version
  • Security > New Features 2025 Recommended:
    CategoryRecommended
    Validationzod, valibot
    HTTPky, ofetch
    Statezustand, jotai
    ORMdrizzle, prisma
    Authlucia, better-auth
    </complexity_and_dependencies>
    <ai_era_protocols>

🤖 PROTOCOL 7: AI-ERA CONSIDERATIONS

When Building AI Features:

  1. Validate AI outputs - Never trust raw LLM responses
  2. Rate limit AI calls - Prevent cost explosions
  3. Sanitize before display - AI can generate malicious content
  4. Log AI interactions - For debugging and compliance When AI is Writing Code:
  5. Verify imports exist - AI hallucinates packages
  6. Check types are correct - AI guesses at APIs
  7. Test edge cases - AI misses boundary conditions
  8. Review security - AI takes shortcuts </ai_era_protocols> <audit_and_reference>

✅ QUICK AUDIT CHECKLIST

Before committing ANY code:

  • No hallucinated imports (verified packages exist)
  • No security shortcuts (CORS, eval, hardcoded secrets)
  • No lazy placeholders (// TODO, empty functions)
  • Functions < 50 lines, files < 300 lines
  • Dependencies audited (npm audit clean)
  • Types are strict (no any)

🔗 CROSS-SKILL INTEGRATION

When Using...Clean Code Adds...
@frontend-designSecurity defaults, no eval, CSP awareness
@backend-designInput validation, no raw SQL, Zero Trust
@tdd-masteryNo placeholders (tests enforce completeness)
@planning-masteryModularity guides task breakdown
@brainstormingSOLID/YAGNI guide architecture decisions
@debug-masteryLogging standards, no silent failures
</audit_and_reference>

© xenitV1, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/clean-code of xenitV1/claude-code-maestro.

Open the folder on GitHubat commit 924315b

Compare with similar skills

Clean Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clean Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clean Code this skillxenitV1/claude-code-maestro229—~1.5kAutomated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT
Constraint-Driven Developmentaddyosmani/agent-skills103k2 repos~5.2kAutomated safety check: PassMIT
Skill Doli Code ReviewDolibarr/dolibarr7.7k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    103k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed
  • Skill Doli Code Review

    Dolibarr/dolibarr

    Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

    7.7k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Ponytail Lazy Developer Mode

    DietrichGebert/ponytail

    Makes the agent pick the laziest solution that works: skip unneeded work, reuse what exists, prefer the standard library and platform features, and keep diffs small.

    158k GitHub stars~871 tokensUpdated today
    DevelopmentAuto-check passed

More from xenitV1/claude-code-maestro

All 13 skills in this repo
  • Ralph Wiggum

    xenitV1/claude-code-maestro

    Surgical Debugger & Code Optimizer. An agent skill from xenitV1/claude-code-maestro.

    229 GitHub starsUsed in 1 repo~795 tokens
    Auto-check: notes
  • Maestro

    xenitV1/claude-code-maestro

    A skill your agent uses when you need to act as an Elite Software Architect (Maestro) to manage complex repositories.

    229 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Backend Design

    xenitV1/claude-code-maestro

    Elite Tier Backend standards, including Vertical Slice Architecture, Zero Trust Security, and High-Performance API protocols.

    229 GitHub stars~2.1k tokensUpdated 8 mo ago
    Auto-check: notes
  • Brainstorming

    xenitV1/claude-code-maestro

    Design-first methodology. An agent skill from xenitV1/claude-code-maestro.

    229 GitHub stars~2k tokensUpdated 8 mo ago
    Auto-check passed
  • Browser Extension

    xenitV1/claude-code-maestro

    Master specialized skill for building 2025/2026-grade browser extensions.

    229 GitHub stars~1.2k tokensUpdated 8 mo ago
    Auto-check: notes
  • Debug Mastery

    xenitV1/claude-code-maestro

    Systematic debugging methodology with 4-phase process, root cause tracing, and elite observability standards.

    229 GitHub stars~2.5k tokensUpdated 8 mo ago
    Auto-check: notes

Categories

Questions about Clean Code

What does Clean Code do?

The Foundation Skill. An agent skill from xenitV1/claude-code-maestro. Clean Code is an agent skill from xenitV1/claude-code-maestro. The Foundation Skill.

When should I use Clean Code?

Clean Code fits situations like: ALL code output - prevents hallucinations; enforces security; ensures quality.

How do I install Clean Code in Claude Code?

Run `npx skills add xenitV1/claude-code-maestro --skill clean-code -a claude-code`. Or copy the skill folder (skills/clean-code in xenitV1/claude-code-maestro) into .claude/skills/clean-code in your project. Claude Code loads it when a task matches its description.

How do I install Clean Code in Codex?

Run `npx skills add xenitV1/claude-code-maestro --skill clean-code -a codex`. Or copy the skill folder (skills/clean-code in xenitV1/claude-code-maestro) into .agents/skills/clean-code in your project. Codex loads it when a task matches its description.

Can I use Clean Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xenitV1/claude-code-maestro --skill clean-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clean-code, .gemini/skills/clean-code, .github/skills/clean-code and .opencode/skills/clean-code in your project.

What does Clean Code need to run?

Going by SKILL.md and its folder, Clean Code needs the command-line tools its instructions call (npm and pip). Our summary lists: Node.js.

Does Clean Code access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Clean Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clean Code use?

Clean Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clean Code use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clean Code?

Skills that share tags, products or a category with Clean Code: Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.3k stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Systematic Code Refactoring (luongnv89/claude-howto, 42k stars) and Constraint-Driven Development (addyosmani/agent-skills, 103k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clean Code?

xenitV1 (a GitHub user) maintains it in xenitV1/claude-code-maestro, which has 229 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on January 24, 2026.

Source: xenitV1/claude-code-maestro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.