ubs
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The installer (install.sh) and the main runner (ubs) are designed to fetch and execute scripts from the vendor's official GitHub repository. install.sh uses a common curl-to-bash pattern, while ubs downloads language-specific scanning modules lazily at runtime. These operations are secured by hardcoded SHA-256 checksums and optional minisign signature verification to ensure supply-chain integrity.
- [EXTERNAL_DOWNLOADS]: To provide accurate semantic analysis for JavaScript and TypeScript, the tool automatically provisions a verified version of the ast-grep binary from its official GitHub releases if it is not already available on the system.
- [COMMAND_EXECUTION]: The meta-runner orchestrates task dispatch to various system utilities and language interpreters, including ripgrep, ast-grep, and the system's python3 or node runtimes, to perform static analysis and report findings.
- [CREDENTIALS_UNSAFE]: The repository contains an extensive test suite with intentionally buggy fixtures. These files include hardcoded examples of API keys, password salts, and secrets (e.g., simulated Stripe and AWS credentials) used solely to verify the scanner's ability to detect such patterns.
- [SAFE]: System modifications performed by the installer, such as adding binaries to the PATH via shell configuration files (~/.bashrc, ~/.zshrc) and setting up git pre-commit or Claude Code save hooks, are standard functionalities for a developer-oriented CLI utility.
- [SAFE]: The presence of homoglyphs, zero-width characters, and Right-to-Left (RTL) override patterns in the edge-cases/ directory is part of the tool's self-testing framework and is used to validate detection logic for those specific classes of obfuscation.
Audit Metadata