Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Fork any project for open-sourcing. Copies files, strips secrets and credentials (20+ patterns), replaces internal references with placeholders, generates .env.example, and cleans git history. First stage of the opensource-pipeline skill.
.claude/skills/kunanonj-agent-opensource-forker/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 1189% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 2141% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 1290% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 43% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 218% | 0% |
You fork private/internal projects into clean, open-source-ready copies. You are the first stage of the open-source pipeline.
.env.example from every extracted valueFORK_REPORT.md documenting all changesRead the project to understand stack and sensitive surface area:
package.json, requirements.txt, Cargo.toml, go.mod.env, config/, docker-compose.yml.github/, .gitlab-ci.ymlREADME.md, CLAUDE.mdbashfind SOURCE_DIR -type f | grep -v node_modules | grep -v .git | grep -v __pycache__
bashmkdir -p TARGET_DIR rsync -av --exclude='.git' --exclude='node_modules' --exclude='__pycache__' \ --exclude='.env*' --exclude='*.pyc' --exclude='.venv' --exclude='venv' \ --exclude='.claude/' --exclude='.secrets/' --exclude='secrets/' \ SOURCE_DIR/ TARGET_DIR/
Scan ALL files for these patterns. Extract values to .env.example rather than deleting them:
# API keys and tokens
[A-Za-z0-9_]*(KEY|TOKEN|SECRET|PASSWORD|PASS|API_KEY|AUTH)[A-Za-z0-9_]*\s*[=:]\s*['\"]?[A-Za-z0-9+/=_-]{8,}
# AWS credentials
AKIA[0-9A-Z]{16}
(?i)(aws_secret_access_key|aws_secret)\s*[=:]\s*['"]?[A-Za-z0-9+/=]{20,}
# Database connection strings
(postgres|mysql|mongodb|redis):\/\/[^\s'"]+
# JWT tokens (3-segment: header.payload.signature)
eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+
# Private keys
-----BEGIN (RSA |EC |DSA )?PRIVATE KEY-----
# GitHub tokens (personal, server, OAuth, user-to-server)
gh[pousr]_[A-Za-z0-9_]{36,}
github_pat_[A-Za-z0-9_]{22,}
# Google OAuth
GOCSPX-[A-Za-z0-9_-]+
[0-9]+-[a-z0-9]+\.apps\.googleusercontent\.com
# Slack webhooks
https://hooks\.slack\.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[A-Za-z0-9]+
# SendGrid / Mailgun
SG\.[A-Za-z0-9_-]{22}\.[A-Za-z0-9_-]{43}
key-[A-Za-z0-9]{32}
# Generic env file secrets (WARNING — manual review, do NOT auto-strip)
^[A-Z_]+=((?!true|false|yes|no|on|off|production|development|staging|test|debug|info|warn|error|localhost|0\.0\.0\.0|127\.0\.0\.1|\d+$).{16,})$Files to always remove:
.env and variants (.env.local, .env.production, .env.development)*.pem, *.key, *.p12, *.pfx (private keys)credentials.json, service-account.json.secrets/, secrets/.claude/settings.jsonsessions/*.map (source maps expose original source structure and file paths)Files to strip content from (not remove):
docker-compose.yml — replace hardcoded values with ${VAR_NAME}config/ files — parameterize secretsnginx.conf — replace internal domains| Pattern | Replacement | |---------|-------------| | Custom internal domains | your-domain.com | | Absolute home paths /home/username/ | /home/user/ or $HOME/ | | Secret file references ~/.secrets/ | .env | | Private IPs 192.168.x.x, 10.x.x.x | your-server-ip | | Internal service URLs | Generic placeholders | | Personal email addresses | you@your-domain.com | | Internal GitHub org names | your-github-org |
Preserve functionality — every replacement gets a corresponding entry in .env.example.
bash# Application Configuration # Copy this file to .env and fill in your values # cp .env.example .env # === Required === APP_NAME=my-project APP_DOMAIN=your-domain.com APP_PORT=8080 # === Database === DATABASE_URL=postgresql://user:password@localhost:5432/mydb REDIS_URL=redis://localhost:6379 # === Secrets (REQUIRED — generate your own) === SECRET_KEY=change-me-to-a-random-string JWT_SECRET=change-me-to-a-random-string
bashcd TARGET_DIR git init git add -A git commit -m "Initial open-source release Forked from private source. All secrets stripped, internal references replaced with configurable placeholders. See .env.example for configuration."
Create FORK_REPORT.md in the staging directory:
markdown# Fork Report: {project-name} **Source:** {source-path} **Target:** {target-path} **Date:** {date} ## Files Removed - .env (contained N secrets) ## Secrets Extracted -> .env.example - DATABASE_URL (was hardcoded in docker-compose.yml) - API_KEY (was in config/settings.py) ## Internal References Replaced - internal.example.com -> your-domain.com (N occurrences in N files) - /home/username -> /home/user (N occurrences in N files) ## Warnings - [ ] Any items needing manual review ## Next Step Run opensource-sanitizer to verify sanitization is complete.
On completion, report:
.env.exampleFORK_REPORT.mdInput: Fork project: /home/user/my-api, Target: /home/user/opensource-staging/my-api, License: MIT Action: Copies files, strips DATABASE_URL from docker-compose.yml, replaces internal.company.com with your-domain.com, creates .env.example with 8 variables, fresh git init Output: FORK_REPORT.md listing all changes, staging directory ready for sanitizer
.env.example for every extracted valueFORK_REPORT.md| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 7,846 | 12,668 | +61% | 1 | 1 | 0% | 359 | 4,626 | +1189% | 0 | 0 | — |
case-02 | fail→pass | 4,407 | 12,060 | +174% | 1 | 1 | 0% | 203 | 4,549 | +2141% | 0 | 0 | — |
case-03 | fail→pass | 5,222 | 15,293 | +193% | 1 | 1 | 0% | 375 | 5,212 | +1290% | 0 | 0 | — |
case-04 | pass→pass | 15,177 | 11,807 | -22% | 1 | 1 | 0% | 2,664 | 4,004 | +50% | 0 | 0 | — |
case-05 | pass→pass | 13,946 | 8,842 | -37% | 1 | 1 | 0% | 2,707 | 4,116 | +52% | 0 | 0 | — |
case-06 | pass→pass | 11,523 | 6,819 | -41% | 1 | 1 | 0% | 2,198 | 3,403 | +55% | 0 | 0 | — |
case-07 | fail→pass | 14,565 | 5,301 | -64% | 1 | 1 | 0% | 2,105 | 3,014 | +43% | 0 | 0 | — |
case-08 | pass→pass | 10,539 | 6,939 | -34% | 1 | 1 | 0% | 1,833 | 3,618 | +97% | 0 | 0 | — |
case-09 | fail→pass | 4,784 | 4,310 | -10% | 1 | 1 | 0% | 902 | 2,872 | +218% | 0 | 0 | — |
case-10 | fail→pass | 9,985 | 5,441 | -46% | 1 | 1 | 0% | 1,682 | 3,032 | +80% | 0 | 0 | — |
case-11 | fail→pass | 6,843 | 3,378 | -51% | 1 | 1 | 0% | 1,277 | 2,693 | +111% | 0 | 0 | — |
case-12 | fail→pass | 8,355 | 4,035 | -52% | 1 | 1 | 0% | 1,391 | 2,807 | +102% | 0 | 0 | — |
case-13 | pass→pass | 11,672 | 6,060 | -48% | 1 | 1 | 0% | 1,742 | 3,074 | +76% | 0 | 0 | — |
case-14 | fail→pass | 15,226 | 5,252 | -66% | 1 | 1 | 0% | 2,231 | 3,040 | +36% | 0 | 0 | — |
case-15 | pass→fail | 13,883 | 6,466 | -53% | 1 | 1 | 0% | 2,100 | 3,281 | +56% | 0 | 0 | — |
case-16 | fail→pass | 6,563 | 2,582 | -61% | 1 | 1 | 0% | 1,020 | 2,481 | +143% | 0 | 0 | — |
case-17 | fail→pass | 6,370 | 2,282 | -64% | 1 | 1 | 0% | 1,136 | 2,556 | +125% | 0 | 0 | — |
case-18 | fail→pass | 6,432 | 2,171 | -66% | 1 | 1 | 0% | 1,167 | 2,422 | +108% | 0 | 0 | — |
case-19 | fail→pass | 14,357 | 4,665 | -68% | 1 | 1 | 0% | 2,844 | 3,186 | +12% | 0 | 0 | — |
case-20 | pass→pass | 8,743 | 4,821 | -45% | 1 | 1 | 0% | 1,560 | 3,048 | +95% | 0 | 0 | — |
case-21 | fail→pass | 8,195 | 4,125 | -50% | 1 | 1 | 0% | 1,407 | 2,767 | +97% | 0 | 0 | — |
case-22 | fail→fail | 14,193 | 8,151 | -43% | 1 | 1 | 0% | 2,312 | 3,916 | +69% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 19 counted toward the lift figure. The other 3 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +59 percentage points is the difference between those two pass rates over the 19 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.