#
ENJA

ubon

luisfer/ubon

Ubon is a specialized security scanner designed to catch vulnerabilities commonly introduced by AI-generated applications, such as hardcoded API keys, unauthenticated server actions, and prompt-injection sinks.

49 3MITUpdated 2026-08-01

Overview

Traditional linters often overlook unique security flaws introduced by AI coding tools like Cursor, Lovable, and Claude Code. Ubon bridges this gap by scanning codebases for issues such as exposed LLM secrets, insecure edge configurations, client-side environment leaks, and hallucinated imports, integrating directly into CI pipelines and AI developer workflows via the Model Context Protocol (MCP).

Capabilities

  • Static security analysis specialized for AI-generated code
  • Detection of hardcoded LLM keys and secrets
  • Server Action and edge runtime security verification
  • Model Context Protocol (MCP) server integration
  • Agent harness generation and hook configuration for Cursor and Claude Code
  • SARIF and structured JSON output generation

Best for

Scanning AI-assisted codebases for leaked LLM keys and vector database secrets, Validating Server Actions and streaming route security before deployment, Integrating into CI/CD pipelines to output SARIF reports for GitHub code scanning, Serving as an MCP tool for AI assistants to automatically detect and repair security vulnerabilities

Works with

Claude CodeCodexCursor
Evoa Score breakdown= Σ (score × weight)
85
Task usefulness20%100 → +20.0

実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 AIによるcapabilities/use-cases解析

Code quality15%95 → +14.3

実装・指示の品質。 AIによるSKILL.md/README解析

Maintenance15%100 → +15.0

リポジトリがどれだけ活発に保守されているか。 GitHub 最終push日時の新しさ

Documentation12%39 → +4.7

ドキュメントの充実度・分かりやすさ。 README/独自要約の情報量

Security15%100 → +15.0

危険・不審な挙動が無いか。 AIによるセキュリティレビュー

Originality10%90 → +9.0

ありふれたラッパーではない独自性。 AIによる独自性判定

Popularity8%44 → +3.5

コミュニティの採用度。 GitHub Stars/Forks(対数スケール)

Compatibility5%75 → +3.8

対応AIエージェントの広さ。 AIによる対応エージェント判定

Weighted total85.2 / 100

ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →

Security considerations

Ubon executes static analysis on local repositories. Running config files as JavaScript requires explicit authorization flags.

Categories

Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.