Agent skill

Catalog Probe

by nubjs in nubjs/nub

Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog.

MITAuto-check passed

Install Catalog Probe

skills CLI
$ npx skills add nubjs/nub --skill catalog-probe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nubjs/nub catalog-probe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/catalog-probe .claude/skills/catalog-probe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
catalog-probe
GitHub stars
4.4k
Token cost
~2.4k tokens
SKILL.md length
1,230 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog.

  • Works in 5 steps: crates/nub-sandbox/src/catalog_v2.rs —… → crates/nub-sandbox/src/catalog_override.r… → tests/build-jail-search/collate.mjs —… → …
  • SKILL.md covers Before you run anything, Running a sweep, Reading the results — coverage… and The instrument has no test —…, plus 6 more sections
  • Calls node and cargo

What it does

Catalog Probe is an agent skill from nubjs/nub. Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog. Invoke (via the Skill tool) whenever you are about to run, restart, extend, or debug a grant sweep under tests/build-jail-search/, whenever a probe reports HARNESS-ERROR / HARNESS-CRASH / BROKEN-EVEN-WITH-EVERYTHING, whenever you change the catalog SHAPE (the Rust parser, the collator, or the synthesized cell catalogs must all move…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Rust. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.

Example prompts

  • “/catalog-probe”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. crates/nub-sandbox/src/catalog_v2.rs — types, parse, validation, resolution
  2. crates/nub-sandbox/src/catalog_override.rs — grant count and lookup
  3. tests/build-jail-search/collate.mjs — writes the catalog
  4. catalogFor in tests/build-jail-search/search.mjs — synthesizes a catalog per cell, every run
  5. tests/build-jail-search/overrides/ — hand-written entries

What it can do on your machine

Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Catalog Probe loads about 2.4k tokens when it runs. Until then it costs about 230 tokens; SKILL.md has 1,230 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~230
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 1,230 words, ~2,440 tokens.

Download SKILL.mdSave it as .claude/skills/catalog-probe/SKILL.md (or your agent's skills folder).
name
catalog-probe
description
Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog. Invoke (via the Skill tool) whenever you are about to run, restart, extend, or debug a grant sweep under tests/build-jail-search/, whenever a probe reports HARNESS-ERROR / HARNESS-CRASH / BROKEN-EVEN-WITH-EVERYTHING, whenever you change the catalog SHAPE (the Rust parser, the collator, or the synthesized cell catalogs must all move together), or whenever you are about to draw a conclusion from sweep results. Carries the failure modes that have each already cost a full sweep: a binary rebuilt mid-run without the override feature, a pre-flight check that validated an artifact adjacent to the question, editing the harness while a batch runs, and a 54%-silent-failure sweep whose survivors were reported as the corpus.

Running the build-jail catalog probe

The probe measures the minimum capability grant a package's lifecycle scripts need, by walking a 54-state capability space in ascending cost order and taking the first state that reproduces an unjailed control. Its output is the build-jail catalog.

Everything here is a failure that has already happened. None of it is hypothetical.

Before you run anything

1. Build with the override feature, or nothing works.

sh
scripts/rust-build.sh build -p nub-cli --profile fast \
  --features nub-cli/build-jail-catalog-override

Any cargo command on a profile rewrites that profile's binary with ITS features. A cargo test --profile fast in another shell silently strips the override and every subsequent package records a control failure. run-batch.sh snapshots the binary to defend against this, but a bare nub invocation outside the batch still uses the live one.

2. Never edit the harness while a batch is running. Each package is a fresh node search.mjs invocation, so an edit mid-sweep changes the harness under the remaining packages. This has produced a sweep where the first half and the second half were measured by different code — and, in the worst case, 54 of 100 packages crashed because the file changed beneath them.

3. Run one cheap package first as an instrument check.

sh
./run-batch.sh <nub> --force is-odd@3.0.1     # expect verdict=MINIMUM, state=(nothing), 2 cells

If that is not clean, nothing after it means anything.

Running a sweep

sh
./run-batch.sh <nub> --file worklist.txt          # a worklist, one pkg@version per line
./run-batch.sh <nub> --force <pkg>@<version>      # one package, --force re-measures

Long sweeps go in a background shell (run_in_background: true), never a foreground call and never nohup/setsid — a detached run cannot be tracked and never wakes you.

Reading the results — coverage first, always

sh
node watch-sweep.mjs results/runs <since-ms> worklist.txt

Pass the worklist. Without it you get a summary of what succeeded and no idea what did not run. The single most expensive mistake made with this tool was reporting the survivors of a sweep as its result: 54 of 100 packages produced no record, the batch discarded their stderr, and the remaining 46 looked like a finished corpus. The failures are not randomly distributed — heavy native builds fail most, and those are exactly the packages most likely to need a grant, so the surviving sample is biased toward "needs nothing."

Rules for reading a sweep:

  • attempted / recorded / FAILED is the headline, printed at the end of every batch. If FAILED is not zero, you do not have a corpus.
  • A run of identical failures indicts the HARNESS, not the packages. Check the FIRST one and fix that; the other ninety-nine are the same fault repeated.
  • Read the first error in a log, never the last. A node stack trace ends with the version banner, and an install log ends with a summary — the cause is usually ~40 lines earlier. Five successive wrong diagnoses of one package all came from reading the tail.

The instrument has no test — the failure with no symptom

A change to the fixture or to baseline.json is a change to the measuring instrument. Its failure mode is not an error; it is that every package measures as needing NOTHING. Every verdict MINIMUM, coverage 100%, nothing fails. Three times in one session:

  • A hand-written package-lock.json with an empty packages map — nub believed the project had no dependencies. Puppeteer's control fell from 9,629 installed files to 32.
  • A baseline entry using $home/... — the wrong grammar (see sentinels below), so the jail failed to compile and no lifecycle script spawned. Surfaced as failed to spawn, which reads as a nub defect.
  • Worst: a measurement taken during the second window was written up as a finding — "this package's grant dissolved" — when the jail was simply not running.

All three were caught by disbelieving the number, never by a check. Eight packages needing nothing, including ones that cannot work without downloading a binary, is not a measurement.

The pre-flight now runs a FIXTURE CANARY: puppeteer@25.4.0 must install >5000 files and be materialized, or the batch refuses. It asserts the control's SHAPE, not a verdict — a package that legitimately needs nothing looks identical either way, so is-odd cannot catch this. NUB_PROBE_SKIP_CANARY=1 disables it when deliberately testing the fixture.

Never report a measurement taken while the harness was known-broken. Re-run it first.

Three $ vocabularies, and they are not interchangeable

NamespaceValid namesUsed by
Compiler fs sentinels$cache, $tmp (closed set), plus ~/baseline paths, catalog fs rules
Harness path tokens$proj/, $store/, $home/recorded paths, writePaths entries
Network host sets$<name> on the net axisnet rules only

$home is meaningful in the second and invalid in the first. The compiler rejects an unknown sentinel by name and lists the valid ones — that message is what makes this a one-step diagnosis.

Show full SKILL.md (489 more words)Show less

Verdicts

VerdictMeansDo
MINIMUMMeasured. state is the minimal grant.Nothing.
HARNESS-CRASH / HARNESS-TIMEOUTThe probe itself failed.Read harness-stderr.log beside the record. Never a package fact.
HARNESS-ERRORThe catalog override did not engage in the control.Wrong binary, or the harness emits a catalog shape the parser rejects.
BROKEN-IN-ENVIRONMENTFails under npm too, same signature.Grant nothing. Check needsInvestigation.
BROKEN-EVEN-WITH-EVERYTHINGFails jailed at the widest grant, but npm succeeds.A nub defect — the most valuable output. Never a grant gap.

Changing the catalog shape — five places move together

Written in one place, read in four. Missing one fails as something else entirely: a shape change that reached the parser but not the harness produced a hundred-package sweep in which every package reported that the override had not engaged, which reads as a broken binary.

  1. crates/nub-sandbox/src/catalog_v2.rs — types, parse, validation, resolution
  2. crates/nub-sandbox/src/catalog_override.rs — grant count and lookup
  3. tests/build-jail-search/collate.mjs — writes the catalog
  4. catalogFor in tests/build-jail-search/search.mjs — synthesizes a catalog per cell, every run
  5. tests/build-jail-search/overrides/ — hand-written entries

Plus the --selftest assertions, which read the synthesized shape and will silently pass on the wrong one if not updated.

The pre-flight probe catalog must come from catalogFor, never a literal. It is emitted by search.mjs --emit-sample-catalog for exactly this reason. A hand-written probe drifts from what the harness emits, and a catalog with an empty package map is the worst possible probe because it parses under every shape there has ever been.

The oracle, and why it is shaped this way

  • Judge the ARTIFACT, not the exit code. A cell passes only if it reproduces the control on exit code and on the digest of the sorted path list. A hook installer that cannot see the project writes zero of seventeen hooks and exits 0.
  • The control runs TWICE, combined by UNION. Never intersection — that compares on fewer paths, so a cell that failed to write an unstable path still passes and the recorded minimum is too narrow, which is the exact failure the jail exists to avoid.
  • Every other package is held at full grant, so the package under test is the only variable.
  • When the oracle says something impossible, suspect the oracle. "Failed all 55 cells, nondeterministic" was 3 varying paths out of 2,734 — all one timestamped log filename.

Ground truth

  • The tarball manifest, not the packument. They disagree: fsevents@2.3.3's packument declares install: node-gyp rebuild and its published tarball does not. nub runs the tarball.
  • Prefer a global baseline/env entry over a per-package grant or a harness filter. A filter hides one tool's write after the fact and must be re-derived per tool. Two entries already earn their place: PYTHONDONTWRITEBYTECODE=1 and npm_config_logs_max=0, each of which stops a write happening at all rather than filtering it afterwards.
  • Over-granting is the safe direction. The failure to avoid is packages breaking.
  • wiki/design/build-jail.md — the canonical design: capability model, bands, placement
  • .frizz/build-jail-catalog-schema.md — the catalog schema spec
  • rust-build — cargo mechanics and the profile/feature trap

© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/catalog-probe of nubjs/nub.

Open the folder on GitHubat commit 568e73a

Compare with similar skills

Catalog Probe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Catalog Probe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Catalog Probe this skillnubjs/nub4.4k—~2.4kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0
Firecrawl Page Scrape Integrationfirecrawl/firecrawl190k1 repos~944Automated safety check: PassISC
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
Rust TDD Workflowrtk-ai/rtk83k—~753Automated safety check: NotesApache-2.0
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Adds Firecrawl's /scrape endpoint to application code to pull markdown, HTML, links, screenshots or structured data from a single known URL.

    190k GitHub starsUsed in 1 repo~944 tokens
    Data & AnalyticsAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Enforces red-green-refactor for Rust work, with idiomatic test patterns, a naming convention and a pre-commit gate of cargo fmt, clippy and test.

    83k GitHub stars~753 tokensUpdated yesterday
    Testing & QAAuto-check: notes
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes

More from nubjs/nub

All 31 skills in this repo
  • Cpu Reduction

    nubjs/nub

    Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.

    4.4k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.

    4.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Nub Charts

    nubjs/nub

    Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…

    4.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Audit Thread

    nubjs/nub

    A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…

    4.4k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Linux Vm Test

    nubjs/nub

    Run ad-hoc Nub tests and debugging probes on real local Linux guests.

    4.4k GitHub stars~986 tokensUpdated yesterday
    Auto-check passed
  • Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.

    4.4k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Catalog Probe

What does Catalog Probe do?

Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog. Catalog Probe is an agent skill from nubjs/nub. Run the build-jail catalog probe — measure the minimum OS capability grant a package's lifecycle scripts need, sweep a worklist of packages, and collate the results into the catalog.

How do I install Catalog Probe in Claude Code?

Run `npx skills add nubjs/nub --skill catalog-probe -a claude-code`. Or copy the skill folder (.claude/skills/catalog-probe in nubjs/nub) into .claude/skills/catalog-probe in your project. Claude Code loads it when a task matches its description.

How do I install Catalog Probe in Codex?

Run `npx skills add nubjs/nub --skill catalog-probe -a codex`. Or copy the skill folder (.claude/skills/catalog-probe in nubjs/nub) into .agents/skills/catalog-probe in your project. Codex loads it when a task matches its description.

Can I use Catalog Probe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill catalog-probe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/catalog-probe, .gemini/skills/catalog-probe, .github/skills/catalog-probe and .opencode/skills/catalog-probe in your project.

What does Catalog Probe need to run?

Going by SKILL.md and its folder, Catalog Probe needs the command-line tools its instructions call (node and cargo).

Does Catalog Probe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Catalog Probe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Catalog Probe use?

Catalog Probe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Catalog Probe use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Catalog Probe?

Skills that share tags, products or a category with Catalog Probe: Update V8 Version (openinterpreter/openinterpreter, 69k stars), Firecrawl Page Scrape Integration (firecrawl/firecrawl, 190k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and Rust TDD Workflow (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Catalog Probe?

nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,372 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.