ui-checkstyle-e8d87d — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ui-checkstyle-e8d87d (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The UI Checkstyle GitHub workflow (.github/workflows/ui-checkstyle.yml) runs three per-area jobs: lint-src (openmetadata-ui/src/main/resources/ui/src/...), lint-playwright (.../playwright/...), lint-core-components (openmetadata-ui-core-components/src/main/resources/ui/src/...). Each job reformats only the files changed in the PR and fails if the reformat produces any diff — i.e. the committed tree must already be formatted.
This skill runs the same sequence locally so the CI never has to ask.
eslint", "fix the UI format", "apply UI format", or similar.
UI Checkstyle / lint-src|lint-playwright|lint-core-componentsfailure (the bot lists the modified files in the job summary).
.ts/.tsx/.js/.jsx/.json under the three UI trees — before opening a PR or pushing a commit that touches UI.
--src (default for files under openmetadata-ui/.../ui/src/)--playwright (files under .../ui/playwright/)--core-components (files under openmetadata-ui-core-components/...)--all — run all three areas--check — verify only: run the sequence in a dry-run pass and reportwhich files are still dirty, without writing. Useful before push.
If invoked with no flag, auto-detect the affected areas from git diff --name-only origin/main...HEAD and run only those.
For each area you are running against:
# from the repo root
git diff --name-only origin/main...HEAD -- \
'openmetadata-ui/src/main/resources/ui/src/**/*.{ts,tsx,js,jsx,json}' \
| sed 's|openmetadata-ui/src/main/resources/ui/||' > /tmp/src_files.txt
git diff --name-only origin/main...HEAD -- \
'openmetadata-ui/src/main/resources/ui/playwright/**/*.{ts,tsx,js,jsx}' \
| sed 's|openmetadata-ui/src/main/resources/ui/||' > /tmp/pw_files.txt
git diff --name-only origin/main...HEAD -- \
'openmetadata-ui-core-components/**/*.{ts,tsx,js,jsx,json}' \
| sed 's|openmetadata-ui-core-components/src/main/resources/ui/||' \
> /tmp/core_files.txtSkip any list that is empty — that area has no changes so the CI job for it wouldn't run anyway.
From the corresponding working directory:
cd openmetadata-ui/src/main/resources/ui # or .../openmetadata-ui-core-components/src/main/resources/ui
# 1) imports first — organize-imports-cli only exists for the ui module
cat /tmp/src_files.txt | xargs ./node_modules/.bin/organize-imports-cli
# 2) eslint --fix (same flags CI uses)
NODE_OPTIONS='--max-old-space-size=8192' cat /tmp/src_files.txt \
| xargs ./node_modules/.bin/eslint --no-error-on-unmatched-pattern --fix
# 3) prettier --write — this MUST run after organize-imports because
# organize-imports uses 4-space indentation / drops trailing commas,
# and prettier then puts them back to the repo's 2-space + trailing-comma
# style. Running them in the other order leaves a dirty diff.
cat /tmp/src_files.txt \
| xargs ./node_modules/.bin/prettier \
--config './.prettierrc.yaml' --ignore-path './.prettierignore' \
--writeFor playwright, use the same three commands on /tmp/pw_files.txt. For core-components, the organize-imports step is skipped (no CLI there) — just eslint + prettier.
cd <repo root>
git status --short # should list only .ts/.tsx/.js/.jsx/.json files
git diff --statIf git status --short is empty, the tree is already clean — tell the user and stop.
Do NOT auto-commit. Surface the list of modified files to the user; they decide whether to fold the reformat into the in-progress commit or create a dedicated "Fix UI checkstyle" commit (matches the repo's existing history for bot-triggered formatting-only commits).
--check mode mirrors CI's behavior: run the three commands and thenverify git status --short is empty. Revert any writes before exiting so the user's working tree isn't touched.
surface them — they need a real code change, not a format pass. Warnings (e.g. playwright/no-wait-for-selector) don't fail CI and can be left.
mvn spotless:apply — see thejava-checkstyle skill.
tsc) are a separate concern and arenot fixed by this skill — the tsc-src / tsc-playwright jobs are currently either skipped or have their own failures surfaced via the CI report.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.