Token导航 LogoToken导航TokenDH.com
研究检索执行命令github未标认证来源可访问clear审计异常

ubs瑞银

Agent Skill

ubs 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

1,423

周安装

57

GitHub Stars

63

下载量

461
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:ubs(瑞银)
来源仓库:https://github.com/dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations
仓库路径:skills/ubs
安装命令:
npx skills add https://github.com/dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations --skill ubs
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations --skill ubs

简介

ubs 用于查找、检索和筛选相关信息。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中根据关键词、任务场景或来源线索快速定位候选结果时使用。
  • 可结合来源仓库、安装命令和原始 README 继续核验具体用法。
  • 安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。
  • ubs 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

UBS - Ultimate Bug Scanner

Static analysis tool built for AI coding workflows. Catches bugs that AI agents commonly introduce: null safety, async/await issues, security holes, memory leaks. Scans JS/TS, Python, Go, Rust, Java, C++, Ruby, Swift in 3-5 seconds.

Why This Exists

AI agents move fast. Bugs move faster. You're shipping features in minutes, but:

  • Null pointer crashes slip through
  • Missing await causes silent failures
  • XSS vulnerabilities reach production
  • Memory leaks accumulate

UBS is the quality gate: scan before commit, fix before merge.

Golden Rule

ubs <changed-files> --fail-on-warning

Exit 0 = safe to commit. Exit 1 = fix and re-run.

Essential Commands

Quick Scans (Use These)

ubs file.ts file2.py                    # Specific files (< 1s)
ubs $(git diff --name-only --cached)    # Staged files
ubs --staged                            # Same, cleaner syntax
ubs --diff                              # Working tree vs HEAD

Full Project Scans

ubs .                                   # Current directory
ubs /path/to/project                    # Specific path
ubs --only=js,python src/               # Language filter (faster)

CI/CD Mode

ubs --ci --fail-on-warning .            # Strict mode for CI
ubs --format=json .                     # Machine-readable
ubs --format=sarif .                    # GitHub code scanning

Output Format

⚠️  Category (N errors)
    file.ts:42:5 – Issue description
    💡 Suggested fix
Exit code: 1

Parse: file:line:col → location | 💡 → how to fix | Exit 0/1 → pass/fail

The 18 Detection Categories

Critical (Always Fix)

CategoryWhat It Catches
Null SafetyUnguarded property access, missing null checks
SecurityXSS, injection, prototype pollution, hardcoded secrets
Async/AwaitMissing await, unhandled rejections, race conditions
Memory LeaksEvent listeners without cleanup, timer leaks
Type Coercion== vs ===, parseInt without radix, NaN comparison

Important (Production Risk)

CategoryWhat It Catches
Division SafetyDivision without zero check
Resource LifecycleUnclosed files, connections, context managers
Error HandlingEmpty catch blocks, swallowed errors
Promise Chains.then() without .catch()
Array MutationsMutating during iteration

Code Quality (Contextual)

CategoryWhat It Catches
Debug Codeconsole.log, debugger, print() statements
TODO MarkersTODO, FIXME, HACK comments
Type SafetyTypeScript any usage
ReadabilityComplex ternaries, deep nesting

Language-Specific Detection

LanguageKey Patterns
JavaScript/TypeScriptinnerHTML XSS, eval(), missing await, React hooks deps
Pythoneval(), open() without with, missing encoding=, None checks
GoNil pointer, goroutine leaks, defer symmetry, context cancel
Rust.unwrap() panics, unsafe blocks, Option handling
JavaResource leaks (try-with-resources), null checks, JDBC
C/C++Buffer overflows, strcpy(), memory leaks, use-after-free
Rubyeval(), send(), instance_variable_set
SwiftForce unwrap (!), ObjC bridging issues

Profiles

ubs --profile=strict .    # Fail on warnings, enforce high standards
ubs --profile=loose .     # Skip TODO/debug nits when prototyping

Category Packs (Focused Scans)

ubs --category=resource-lifecycle .    # Python/Go/Java resource hygiene

Narrows scan to relevant languages and suppresses unrelated categories.

Comparison Mode (Regression Detection)

# Capture baseline
ubs --ci --report-json .ubs/baseline.json .

# Compare against baseline
ubs --ci --comparison .ubs/baseline.json --report-json .ubs/latest.json .

Useful for CI to detect regressions vs. main branch.

Output Formats

FormatFlagUse Case
text(default)Human-readable terminal output
json--format=jsonMachine parsing, scripting
jsonl--format=jsonlLine-delimited, streaming
sarif--format=sarifGitHub code scanning
html--html-report=file.htmlPR attachments, dashboards

Inline Suppression

When a finding is intentional:

eval(trustedCode);  // ubs:ignore

// ubs:ignore-next-line
dangerousOperation();

Exit Codes

CodeMeaning
0No critical issues (safe to commit)
1Critical issues or warnings (with --fail-on-warning)
2Environment error (missing ast-grep, etc.)

Doctor Command

ubs doctor                # Check environment
ubs doctor --fix          # Auto-fix missing dependencies

Checks: curl/wget, ast-grep, ripgrep, jq, typos, Node.js + TypeScript.

Agent Integration

UBS auto-configures hooks for coding agents during install:

AgentHook Location
Claude Code.claude/hooks/on-file-write.sh
Cursor.cursor/rules
Codex CLI.codex/rules/ubs.md
Gemini.gemini/rules
Windsurf.windsurf/rules
Cline.cline/rules

Claude Code Hook Pattern

#!/bin/bash
# .claude/hooks/on-file-write.sh
if [[ "$FILE_PATH" =~ \.(js|jsx|ts|tsx|py|go|rs|java|rb)$ ]]; then
  echo "🔬 Quality check running..."
  if ubs "${PROJECT_DIR}" --ci 2>&1 | head -30; then
    echo "✅ No critical issues"
  else
    echo "⚠️  Issues detected - review above"
  fi
fi

Git Pre-Commit Hook

#!/bin/bash
# .git/hooks/pre-commit
echo "🔬 Running bug scanner..."
if ! ubs . --fail-on-warning 2>&1 | tail -30; then
  echo "❌ Critical issues found. Fix or: git commit --no-verify"
  exit 1
fi
echo "✅ Quality check passed"

Performance

Small (5K lines):     0.8 seconds
Medium (50K lines):   3.2 seconds
Large (200K lines):   12 seconds
Huge (1M lines):      58 seconds

10,000+ lines per second. Use --jobs=N to control parallelism.

Speed Tips

  1. Scope to changed files: ubs src/file.ts (< 1s) vs ubs. (30s)
  2. Use --staged or --diff: Only scan what you're committing
  3. Language filter: --only=js,python skips irrelevant scanners
  4. Skip categories: --skip=11,14 to skip debug/TODO markers

Fix Workflow

1. Read finding → category + fix suggestion
2. Navigate file:line:col → view context
3. Verify real issue (not false positive)
4. Fix root cause (not symptom)
5. Re-run ubs <file> → exit 0
6. Commit

Bug Severity Guide

  • Critical (always fix): Null safety, XSS/injection, async/await, memory leaks
  • Important (production): Type narrowing, division-by-zero, resource leaks
  • Contextual (judgment): TODO/FIXME, console logs

Common Anti-Patterns

Don'tDo
Ignore findingsInvestigate each
Full scan per editScope to changed files
Fix symptom (if (x) {x.y})Fix root cause (x?.y)
Suppress without understandingVerify false positive first

Installation

# One-liner (recommended)
curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/ultimate_bug_scanner/master/install.sh?$(date +%s)" | bash -s -- --easy-mode

# Manual
curl -fsSL https://raw.githubusercontent.com/Dicklesworthstone/ultimate_bug_scanner/master/ubs \
  -o /usr/local/bin/ubs && chmod +x /usr/local/bin/ubs

Custom AST Rules

mkdir -p ~/.config/ubs/rules

cat > ~/.config/ubs/rules/no-console.yml <<'EOF'
id: custom.no-console
language: javascript
rule:
  pattern: console.log($$$)
severity: warning
message: "Remove console.log before production"
EOF

ubs . --rules=~/.config/ubs/rules

Excluding Paths

ubs . --exclude=legacy,generated,vendor

Auto-ignored: node_modules, .venv, dist, build, target, editor caches.

Session Logs

ubs sessions --entries 1    # View latest install session

Integration with Flywheel

ToolIntegration
BV--beads-jsonl=out.jsonl exports findings for Beads
CASSSearch past sessions for similar bug patterns
CMExtract rules from UBS findings
Agent MailNotify agents of scan results
DCGUBS runs inside DCG protection

Troubleshooting

ErrorFix
"Environment error" (exit 2)ubs doctor --fix
"ast-grep not found"brew install ast-grep or cargo install ast-grep
Too many false positivesUse --skip=N or // ubs:ignore
Slow scansScope to files: ubs <file> not ubs.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

26.69%
按下载量换算123

Gemini CLI

21.33%
按下载量换算98

OpenCode

18.47%
按下载量换算85

Codex

12.8%
按下载量换算59

Antigravity

8.17%
按下载量换算38

windsurf

3.46%
按下载量换算16

安全审计

Gen Agent Trust Hub

未通过

Socket

通过

Snyk

未通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 npx skills add https://github.com/dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations --skill ubs;npx skills add dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations --skill "ubs" 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。

来源信息

继续浏览同类 Skills