ubs
Scan Code for Bugs Before Commit
AI-assisted changes can introduce null safety, async, security, and resource bugs before review. This skill gives Claude, Codex, and Claude Code a concise workflow for running UBS as a quality gate.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ubs" from https://skillstore.io/skills/dicklesworthstone-ubs.md and its manifest at https://skillstore.io/api/skills/dicklesworthstone-ubs/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "ubs". Ask the agent to scan staged files before commit.
Expected outcome:
The agent reports critical findings first, identifies affected files, and recommends the smallest safe fixes.
Using "ubs". Ask for CI integration guidance.
Expected outcome:
The response outlines strict scan mode, report artifacts, pull request annotations, and a baseline comparison strategy.
Using "ubs". Ask for custom rule planning.
Expected outcome:
The response names candidate patterns, affected languages, validation checks, and suppression guidance for intentional exceptions.
Security Audit
CriticalMost static findings are false positives caused by Markdown tables, code fences, and inline examples. The install guidance still includes a real curl-to-bash command and a remote executable download into /usr/local/bin. The skill also describes persistent agent hook configuration, so it is not suitable for automatic marketplace installation without review.
Confirmed security concerns (3)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โก Contains scripts (4)
โ๏ธ External commands (74)
๐ Network access (2)
๐ Filesystem access (6)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/dicklesworthstone-ubs/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/dicklesworthstone-ubs?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/dicklesworthstone-ubs?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/dicklesworthstone-ubs/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/dicklesworthstone-ubs.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
Dicklesworthstone. (2026). ubs security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/dicklesworthstone-ubs/audits/9BibTeX citation
@techreport{dicklesworthstone-dicklesworthstone-ubs-2026,
author = {Dicklesworthstone},
title = {ubs security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/dicklesworthstone-ubs/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ubs security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "Dicklesworthstone"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/dicklesworthstone-ubs/audits/9"
identifiers:
- type: other
value: "skillstore:dicklesworthstone-ubs:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Pre-Commit Review
Run UBS on staged or changed files before committing AI-assisted code.
CI Quality Gate
Add strict UBS scans and machine-readable reports to pull request pipelines.
Agent Workflow Guardrails
Give coding agents a repeatable scan, fix, and re-run loop before handoff.
Try These Prompts
Run UBS on my changed files and summarize blocking issues, likely causes, and the safest next fixes.
Review these UBS findings, separate confirmed bugs from likely false positives, and explain each decision briefly.
Design a UBS CI quality gate for this repository, including failure rules, report formats, and rollout steps.
Propose custom UBS AST rules for our recurring bug patterns and explain how to validate them safely.
Best Practices
- Run UBS on changed files first, then broaden scope before release or merge.
- Review every high severity finding before suppressing it.
- Pin installer sources and verify checksums before adding UBS to shared environments.
Avoid
- Do not pipe remote installer scripts directly into a shell without review.
- Do not suppress UBS findings until the underlying code path is understood.
- Do not let automated hooks change agent behavior without explicit team approval.
Frequently Asked Questions
What does this skill help me do?
Does this skill include the UBS scanner?
Which tools can use this skill?
Can UBS replace code review?
Is automatic installation recommended?
Can teams customize checks?
Developer Details
Author
DicklesworthstoneLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
72d5025b022c77f7a51bdf5c1637c689c80e89d1
Maintenance freshness
7/18/2026
Usage
6 downloads ยท 183 views
File structure
๐ SKILL.md