Update V8 Version
openinterpreter/openinterpreter
Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.
Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog.
$ npx skills add nubjs/nub --skill catalog-probe -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nubjs/nub catalog-probe --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/catalog-probe .claude/skills/catalog-probe && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "catalog-probe" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probe into .claude/skills/catalog-probe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "catalog-probe", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nubjs/nub --skill catalog-probe -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nubjs/nub catalog-probe --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/catalog-probe .agents/skills/catalog-probe && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "catalog-probe" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probe into .agents/skills/catalog-probe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "catalog-probe", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill catalog-probe -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nubjs/nub catalog-probe --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/catalog-probe .cursor/skills/catalog-probe && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "catalog-probe" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probe into .cursor/skills/catalog-probe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "catalog-probe", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nubjs/nub.git --path .claude/skills/catalog-probe--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nubjs/nub --skill catalog-probe -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nubjs/nub catalog-probe --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/catalog-probe .gemini/skills/catalog-probe && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "catalog-probe" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probe into .gemini/skills/catalog-probe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "catalog-probe", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nubjs/nub catalog-probeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nubjs/nub --skill catalog-probe -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/catalog-probe .github/skills/catalog-probe && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "catalog-probe" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probe into .github/skills/catalog-probe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "catalog-probe", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill catalog-probe -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nubjs/nub catalog-probe --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/catalog-probe .opencode/skills/catalog-probe && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "catalog-probe" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/catalog-probe into .opencode/skills/catalog-probe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "catalog-probe", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
catalog-probeRun the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog.
Catalog Probe is an agent skill from nubjs/nub. Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog. Invoke (via the Skill tool) whenever you are about to run, restart, extend, or debug a grant sweep under tests/build-jail-search/, whenever a probe reports HARNESS-ERROR / HARNESS-CRASH / BROKEN-EVEN-WITH-EVERYTHING, whenever you change the catalog SHAPE (the Rust parser, the collator, or the synthesized cell catalogs must all move…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with Rust. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
nodecargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Catalog Probe loads about 2.4k tokens when it runs. Until then it costs about 230 tokens; SKILL.md has 1,230 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 1,230 words, ~2,440 tokens.
.claude/skills/catalog-probe/SKILL.md (or your agent's skills folder).The probe measures the minimum capability grant a package's lifecycle scripts need, by walking a 54-state capability space in ascending cost order and taking the first state that reproduces an unjailed control. Its output is the build-jail catalog.
Everything here is a failure that has already happened. None of it is hypothetical.
1. Build with the override feature, or nothing works.
scripts/rust-build.sh build -p nub-cli --profile fast \
--features nub-cli/build-jail-catalog-overrideAny cargo command on a profile rewrites that profile's binary with ITS features. A
cargo test --profile fast in another shell silently strips the override and every subsequent
package records a control failure. run-batch.sh snapshots the binary to defend against this, but a
bare nub invocation outside the batch still uses the live one.
2. Never edit the harness while a batch is running. Each package is a fresh
node search.mjs invocation, so an edit mid-sweep changes the harness under the remaining packages.
This has produced a sweep where the first half and the second half were measured by different code —
and, in the worst case, 54 of 100 packages crashed because the file changed beneath them.
3. Run one cheap package first as an instrument check.
./run-batch.sh <nub> --force is-odd@3.0.1 # expect verdict=MINIMUM, state=(nothing), 2 cellsIf that is not clean, nothing after it means anything.
./run-batch.sh <nub> --file worklist.txt # a worklist, one pkg@version per line
./run-batch.sh <nub> --force <pkg>@<version> # one package, --force re-measuresLong sweeps go in a background shell (run_in_background: true), never a foreground call and
never nohup/setsid — a detached run cannot be tracked and never wakes you.
node watch-sweep.mjs results/runs <since-ms> worklist.txtPass the worklist. Without it you get a summary of what succeeded and no idea what did not run. The single most expensive mistake made with this tool was reporting the survivors of a sweep as its result: 54 of 100 packages produced no record, the batch discarded their stderr, and the remaining 46 looked like a finished corpus. The failures are not randomly distributed — heavy native builds fail most, and those are exactly the packages most likely to need a grant, so the surviving sample is biased toward "needs nothing."
Rules for reading a sweep:
attempted / recorded / FAILED is the headline, printed at the end of every batch. If
FAILED is not zero, you do not have a corpus.A change to the fixture or to baseline.json is a change to the measuring instrument. Its
failure mode is not an error; it is that every package measures as needing NOTHING. Every verdict
MINIMUM, coverage 100%, nothing fails. Three times in one session:
package-lock.json with an empty packages map — nub believed the project had no
dependencies. Puppeteer's control fell from 9,629 installed files to 32.$home/... — the wrong grammar (see sentinels below), so the jail failed
to compile and no lifecycle script spawned. Surfaced as failed to spawn, which reads as a
nub defect.All three were caught by disbelieving the number, never by a check. Eight packages needing nothing, including ones that cannot work without downloading a binary, is not a measurement.
The pre-flight now runs a FIXTURE CANARY: puppeteer@25.4.0 must install >5000 files and be
materialized, or the batch refuses. It asserts the control's SHAPE, not a verdict — a package that
legitimately needs nothing looks identical either way, so is-odd cannot catch this.
NUB_PROBE_SKIP_CANARY=1 disables it when deliberately testing the fixture.
Never report a measurement taken while the harness was known-broken. Re-run it first.
$ vocabularies, and they are not interchangeable| Namespace | Valid names | Used by |
|---|---|---|
| Compiler fs sentinels | $cache, $tmp (closed set), plus ~/ | baseline paths, catalog fs rules |
| Harness path tokens | $proj/, $store/, $home/ | recorded paths, writePaths entries |
| Network host sets | $<name> on the net axis | net rules only |
$home is meaningful in the second and invalid in the first. The compiler rejects an unknown
sentinel by name and lists the valid ones — that message is what makes this a one-step diagnosis.
| Verdict | Means | Do |
|---|---|---|
MINIMUM | Measured. state is the minimal grant. | Nothing. |
HARNESS-CRASH / HARNESS-TIMEOUT | The probe itself failed. | Read harness-stderr.log beside the record. Never a package fact. |
HARNESS-ERROR | The catalog override did not engage in the control. | Wrong binary, or the harness emits a catalog shape the parser rejects. |
BROKEN-IN-ENVIRONMENT | Fails under npm too, same signature. | Grant nothing. Check needsInvestigation. |
BROKEN-EVEN-WITH-EVERYTHING | Fails jailed at the widest grant, but npm succeeds. | A nub defect — the most valuable output. Never a grant gap. |
Written in one place, read in four. Missing one fails as something else entirely: a shape change that reached the parser but not the harness produced a hundred-package sweep in which every package reported that the override had not engaged, which reads as a broken binary.
crates/nub-sandbox/src/catalog_v2.rs — types, parse, validation, resolutioncrates/nub-sandbox/src/catalog_override.rs — grant count and lookuptests/build-jail-search/collate.mjs — writes the catalogcatalogFor in tests/build-jail-search/search.mjs — synthesizes a catalog per cell, every runtests/build-jail-search/overrides/ — hand-written entriesPlus the --selftest assertions, which read the synthesized shape and will silently pass on the
wrong one if not updated.
The pre-flight probe catalog must come from catalogFor, never a literal. It is emitted by
search.mjs --emit-sample-catalog for exactly this reason. A hand-written probe drifts from what
the harness emits, and a catalog with an empty package map is the worst possible probe because it
parses under every shape there has ever been.
fsevents@2.3.3's packument declares
install: node-gyp rebuild and its published tarball does not. nub runs the tarball.baseline/env entry over a per-package grant or a harness filter. A filter
hides one tool's write after the fact and must be re-derived per tool. Two entries already earn
their place: PYTHONDONTWRITEBYTECODE=1 and npm_config_logs_max=0, each of which stops a write
happening at all rather than filtering it afterwards.wiki/design/build-jail.md — the canonical design: capability model, bands, placement.frizz/build-jail-catalog-schema.md — the catalog schema specrust-build — cargo mechanics and the profile/feature trap© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/catalog-probe of nubjs/nub.
Open the folder on GitHubat commit 568e73a
Catalog Probe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Catalog Probe this skillnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Update V8 Versionopeninterpreter/openinterpreter | 69k | 2 repos | ~845 | Automated safety check: Pass | Apache-2.0 | |
| Firecrawl Page Scrape Integrationfirecrawl/firecrawl | 190k | 1 repos | ~944 | Automated safety check: Pass | ISC | |
| Migrate Core Code to Submodulestinyhumansai/openhuman | 42k | — | ~2.6k | Automated safety check: Pass | GPL-3.0 | |
| Rust TDD Workflowrtk-ai/rtk | 83k | — | ~753 | Automated safety check: Notes | Apache-2.0 | |
| Rust Best Practicesfarm-fe/farm | 5.6k | 3 repos | ~1.1k | Automated safety check: Pass | MIT |
openinterpreter/openinterpreter
Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.
firecrawl/firecrawl
Adds Firecrawl's /scrape endpoint to application code to pull markdown, HTML, links, screenshots or structured data from a single known URL.
tinyhumansai/openhuman
Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.
rtk-ai/rtk
Enforces red-green-refactor for Rust work, with idiomatic test patterns, a naming convention and a pre-commit gate of cargo fmt, clippy and test.
farm-fe/farm
Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.
AprilNEA/OpenLogi
Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.
nubjs/nub
Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.
nubjs/nub
Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.
nubjs/nub
Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…
nubjs/nub
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
nubjs/nub
Run ad-hoc Nub tests and debugging probes on real local Linux guests.
nubjs/nub
Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
Works with
Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog. Catalog Probe is an agent skill from nubjs/nub. Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog.
Run `npx skills add nubjs/nub --skill catalog-probe -a claude-code`. Or copy the skill folder (.claude/skills/catalog-probe in nubjs/nub) into .claude/skills/catalog-probe in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nubjs/nub --skill catalog-probe -a codex`. Or copy the skill folder (.claude/skills/catalog-probe in nubjs/nub) into .agents/skills/catalog-probe in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill catalog-probe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/catalog-probe, .gemini/skills/catalog-probe, .github/skills/catalog-probe and .opencode/skills/catalog-probe in your project.
Going by SKILL.md and its folder, Catalog Probe needs the command-line tools its instructions call (node and cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Catalog Probe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Catalog Probe: Update V8 Version (openinterpreter/openinterpreter, 69k stars), Firecrawl Page Scrape Integration (firecrawl/firecrawl, 190k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and Rust TDD Workflow (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,372 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.
Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.