ubs
Terraphim AI: deterministic AI Assistant
Install / Use
npx skills add terraphim/terraphim-aiInstalls into whichever agent you are using.
Cursor Rules
Cursor IDE rules (v2)
Quality Score
Category
Content & MediaSupported Platforms
Our assessment of ubs
ubs scores 62/100 on our quality scale, 641st of 709 Content & Media skills we index.
Its Cursor Rules is 3.3 KB long, split into 3 sections with 3 code examples: a solid amount of guidance for an agent.
It has no GitHub stars yet, so there is no community track record; judge it on its content.
Maintenance, license and trust
- The repository was last updated 9 days ago, so ubs is actively maintained.
- Our last check on 2026-09-27 found the source still online.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
ReviewOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (1 minor note below). An AI review judged it risky: Line 7 instructs the agent to install UBS by piping a remote script directly into bash (`curl ... | bash`), which is a risky pattern in a rules file the agent follows.
- noteInstalls by piping a downloaded script into a shellline 7
**Install:** `curl -sSL https://raw.githubusercontent.com/Dicklesworthstone/ultimate_bug_scanner/master/install.sh | bash`
AI review: risky
- Line 7 instructs the agent to install UBS by piping a remote script directly into bash (`curl ... | bash`), which is a risky pattern in a rules file the agent follows.
- The rule tells the agent to run this externally-installed tool automatically before every commit, increasing the impact if the installer or tool is compromised.
- There is no checksum verification, package-manager install, or other safeguard around the remote shell installer.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
ubs compared with similar skills
All 4 of these similar skills score higher than ubs; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ubs (this skill)by terraphim | 62 | 0 | 9d ago | Cursor Rules |
| Agent-Reachby Panniantong | 100 | 85.9k | 12d ago | CLAUDE.md |
| siyuanby siyuan-note | 100 | 46.5k | today | MCP Server |
| content-research-writerby ComposioHQ | 100 | 75.6k | 10d ago | SKILL.md |
| ad-campaign-analyzerby sickn33 | 100 | 46.9k | 4d ago | SKILL.md |
Frequently asked questions
- How do I install ubs?
- Run
npx skills add terraphim/terraphim-ai. The install tabs above show the steps for each supported agent. - Which AI agents does ubs work with?
- It is written for Cursor, as a Cursor Rules file. Other agents that read the same format can often use it too.
- Is ubs safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (1 minor note below). An AI review judged it risky: Line 7 instructs the agent to install UBS by piping a remote script directly into bash (
curl ... | bash), which is a risky pattern in a rules file the agent follows. It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand. - Is ubs still maintained?
- The repository was last updated 9 days ago, so ubs is actively maintained.
Skill content
View source on GitHub## UBS Quick Reference for AI Agents
UBS stands for "Ultimate Bug Scanner": **The AI Coding Agent's Secret Weapon: Flagging Likely Bugs for Fixing Early On**
**Install:** `curl -sSL https://raw.githubusercontent.com/Dicklesworthstone/ultimate_bug_scanner/master/install.sh | bash`
**Golden Rule:** `ubs --only=<lang> <changed-files>` before every commit. Exit 0 = safe. Exit >0 = fix & re-run.
Always specify language with `--only` to avoid false positives from cross-language scanning.
**Why --only is Critical:**
UBS auto-detects all 8 languages (js, python, cpp, rust, golang, java, ruby, swift) and scans every file with every scanner. Without `--only`:
- Python scanner reports "invalid-syntax" errors on Rust files
- JavaScript scanner flags "loose equality" in Rust code (false critical)
- Wasted time (8x slower) scanning files with wrong language parsers
**Always specify target language to avoid noise and false positives.**
**Commands:**
```bash
# Language-specific scanning (RECOMMENDED)
ubs --only=rust crates/terraphim_automata/src/lib.rs # Rust files only
ubs --only=python test_*.py # Python files only
ubs --only=js desktop/src/lib/*.ts # JavaScript/TypeScript files only
ubs --only=js,python src/ # Multiple languages
# General commands
ubs file.ts file2.py # Specific files (use --only instead)
ubs $(git diff --name-only --cached) # Staged files — before commit
ubs --ci --fail-on-warning . # CI mode — before PR
ubs --help # Full command reference
ubs sessions --entries 1 # Tail the latest install session log
ubs . # Whole project (slow, avoid)
```
**Language Flags Quick Reference:**
| Flag | File Extensions | Use For |
|------|----------------|---------|
| `--only=rust` | .rs | Rust source files |
| `--only=python` | .py, .pyi | Python scripts and tests |
| `--only=js` | .js, .ts, .jsx, .tsx | JavaScript/TypeScript files |
| `--only=cpp` | .c, .cpp, .h, .hpp | C/C++ files |
| `--only=golang` | .go | Go source files |
| `--only=java` | .java | Java source files |
| `--only=ruby` | .rb | Ruby scripts |
| `--only=swift` | .swift | Swift source files |
**Output Format:**
```
⚠️ Category (N errors)
file.ts:42:5 – Issue description
💡 Suggested fix
Exit code: 1
```
Parse: `file:line:col` → location | 💡 → how to fix | Exit 0/1 → pass/fail
**Fix Workflow:**
1. Read finding → category + fix suggestion
2. Navigate `file:line:col` → view context
3. Verify real issue (not false positive)
4. Fix root cause (not symptom)
5. Re-run `ubs <file>` → exit 0
6. Commit
**Speed Critical:** Scope to changed files. `ubs src/file.ts` (< 1s) vs `ubs .` (30s). Never full scan for small edits.
**Bug Severity:**
- **Critical** (always fix): Null safety, XSS/injection, async/await, memory leaks
- **Important** (production): Type narrowing, division-by-zero, resource leaks
- **Contextual** (judgment): TODO/FIXME, console logs
**Anti-Patterns:**
- ❌ Ignore findings → ✅ Investigate each
- ❌ Full scan per edit → ✅ Scope to file
- ❌ Fix symptom (`if (x) { x.y }`) → ✅ Root cause (`x?.y`)
- ❌ Scan without `--only` → ✅ Always specify target language
Related Skills
Agent-Reach
85.9kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
siyuan
46.5kAn open-source, privacy-first, self-hosted knowledge workspace where humans and AI agents work together 开源、隐私优先、自托管的知识工作空间,让人与智能体在此协作
content-research-writer
75.6kAssists in writing high-quality content by conducting research, adding citations, improving hooks, iterating on outlines, and providing real-time feedback on each section. Transforms your writing process from solo effort to collaborative partnership.
ad-campaign-analyzer
46.9kAnalyze cross-channel campaign data, quantify uncertainty, and propose evidence-labeled budget tests without overstating causality.
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
