Install
$ agentstack add skill-avdlee-xcode-disk-cleanup-agent-skill-xcode-disk-cleanup ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Xcode Disk Cleanup
Safety contract
- Treat every cleanup request as permission to audit, not permission to delete.
- Never mutate storage before presenting exact candidate IDs, paths or simulator
identifiers, measured sizes, risks, and regeneration costs.
- Ask the user to approve specific IDs. Broad replies such as “clean Xcode” or
“delete everything” are not itemized approval.
- Default ordinary files and directories to Trash. Explain that space is not
reclaimed until Trash is emptied, and request separate approval before doing so.
- Revalidate identity and running-process usage immediately before mutation.
- Never use wildcards, unbounded
rm -rf,sudo, SIP changes, or manual deletion
inside system-managed CoreSimulator and MobileAsset directories.
- Preserve archives and dSYMs unless the user proves the exact distributed build
is backed up elsewhere and separately approves deletion.
- Never delete
Package.resolved, signing assets, credentials, custom DocSets, the
active Xcode, a running simulator, or an Xcode that uniquely provides a required SDK/toolchain.
- Report summed candidate sizes separately from actual APFS space recovered.
Read references/safety-model.md before applying cleanup.
Workflow
1. Preflight
- Confirm the host is macOS and the bundled script is available.
- Check for active Xcode, Simulator,
xcodebuild, Swift build, test, archive, and
package-resolution processes.
- If builds are active, audit may continue, but defer all cleanup.
- Determine optional source roots for project-local
.buildand.derived-data
scanning. Do not crawl the whole home directory.
2. Run the read-only audit
python3 "${SKILL_DIR}/scripts/xcode_disk_cleanup.py" audit \
--output-dir .xcode-disk-cleanup-audit \
[--scan-root /path/to/projects]
Read both generated files:
.xcode-disk-cleanup-audit/report.md.xcode-disk-cleanup-audit/audit.json
The script audits DerivedData, documentation caches, CocoaPods caches, simulator devices and runtimes (including stale superseded beta runtimes), orphan runtime volumes, simulator dyld caches, Xcode-managed components, Xcode installers, installed Xcodes, archives (including never-distributed orphans), DeviceSupport for every platform, diagnostic logs, XCTest device clones, legacy DocSets, and explicitly requested project roots.
Shared compiler caches (ModuleCache.noindex, precompiled SDK modules) and the global SwiftPM download cache are deliberately out of scope: they are always in use on an active development machine, and clearing them trades real build-time pain for little lasting space. Do not propose them.
3. Validate and enrich findings
Use the category router:
| Finding | Reference | |---|---| | DerivedData, module caches, project .build, CocoaPods | references/generated-data.md | | Simulator devices, runtimes, dyld caches, XCTest clones | references/simulators.md | | Archives, dSYMs, DeviceSupport, logs, DocSets | references/release-artifacts.md | | Xcode DMGs/XIPs and installed Xcodes | references/xcode-installations.md | | Confirmation and deletion behavior | references/safety-model.md |
Do not mechanically accept a scanner classification. Verify uncertain ownership, custom paths, backups, and toolchain requirements.
4. Present the proposal
Sort by recoverable GiB and show:
- Candidate ID
- Category and exact path/identifier
- Recoverable GiB
- Risk: regenerable, destructive, or preserve
- Evidence — a short "why this is stale" phrase (age in days, superseded-by,
missing workspace), not just a classification label
- What must be rebuilt, redownloaded, or permanently lost
- Proposed action
Keep the proposal scannable:
- Render folder candidates as clickable
file://links so the user can inspect
them before approving.
- Hide individual items below roughly 0.5 GiB; the full itemized list stays in
report.md for reference. Do not pad the proposal with a "small items" bucket — it adds questions, not signal.
- Group unavailable simulators into a table per runtime.
- Give every category its own subheading with its total size, even small ones
like documentation caches or orphan archives. A category summarized in a trailing paragraph under another category's table gets overlooked, and overlooked items cannot be meaningfully approved.
Include:
- Total candidate GiB by risk
- Current free disk space
- A warning that APFS cloning and snapshots make candidate sizes non-additive
- A direct request for approval of exact IDs
5. Apply only approved IDs
Invoke apply only after the user explicitly approves the exact IDs shown in the current audit:
python3 "${SKILL_DIR}/scripts/xcode_disk_cleanup.py" apply \
--audit-file .xcode-disk-cleanup-audit/audit.json \
--ids "" "" \
--confirm I_APPROVED_THE_SELECTED_ITEMS \
--output .xcode-disk-cleanup-audit/cleanup-result.json
Simulator device and runtime deletions are irreversible and require a second approval plus:
--confirm-irreversible I_APPROVED_IRREVERSIBLE_SIMULATOR_DELETION
A stale runtime is only proposed when simctl reports it deletable, no installed Xcode SDK resolves to its build, and a newer runtime supersedes it on the same platform. This is the pattern behind leftover beta platforms in Xcode Settings → Components after installing a newer Xcode beta.
Do not pass either confirmation phrase unless the corresponding user approval is present in the conversation.
6. Verify
- Re-run the audit.
- Compare
dffree space before and after. - Distinguish “moved to Trash” from immediately reclaimed space.
- Confirm protected and unapproved candidates remain.
- Report successes, failures, and deferred items.
Xcode installer and application rules
- Search
.xip,.dmg, and.zipinstallers through Spotlight and common
download folders.
- Suggest an installer only when its parsed version matches an installed Xcode;
otherwise report it as uncertain.
- An older Xcode may only be suggested, never automatically selected, when it is
not active/running and a newer same-channel installation exists.
- Spotlight
kMDItemLastUsedDatereflects LaunchServices opens, not command-line
use. Combine it with xcode-select, DEVELOPER_DIR, running processes, .xcode-version, CI scripts, and unique SDK/toolchain evidence.
- Never infer that a stable Xcode supersedes a beta, or vice versa.
Output quality checklist
- [ ] Audit completed without mutation
- [ ] Every item has an exact size and stable ID
- [ ] Candidate and actual recovered space are separate
- [ ] Archives/dSYMs are preserve-by-default
- [ ] Active processes and selected Xcode are protected
- [ ] User approved exact IDs
- [ ] Irreversible operations received separate approval
- [ ] Post-cleanup audit confirms only approved items changed
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: AvdLee
- Source: AvdLee/Xcode-Disk-Cleanup-Agent-Skill
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.