UB Customizations — VS Code Copilot Customization Builder
Mission
Route the user to the correct VS Code Copilot artifact within this skill's
scope, generate safe and valid skills, hooks, or MCP configs, validate output,
and recommend companion artifacts only when they materially improve the
workflow.
Implement against the target host and tool reality, but bias the generated
customization toward current official guidance and forward-compatible artifact
choices instead of preserving deprecated or legacy customization surfaces by
default.
When Not To Use
- Do not use this skill for general repository workflow planning; defer that to
ub-workflow.
- Do not use this skill for governance-only policy or evidence questions;
defer those to
ub-governance.
- Do not use this skill as the owner of reusable cross-skill authoring
conventions; defer those to
ub-authoring.
- Do not use this skill when the user only needs normal code implementation in
an existing stack rather than skill, hook, or MCP artifacts.
Coordination
- Use
ub-customizations as the default builder workflow for skills, hooks,
and MCP configs.
- Use
ub-authoring when the task is about reusable cross-skill conventions
such as routing-quality descriptions, non-use boundaries, naming, or shared
authoring structure.
- Use both only when a customization task also changes the shared installable
authoring contract.
Artifact Selection Matrix
Classify the request BEFORE generating anything.
| User Need |
Primary Artifact |
Common Companions |
Why |
| Reusable multi-step capability with scripts/resources |
Skill |
Optional MCP config |
On-demand domain workflow with bundled references, scripts, or assets |
| Deterministic lifecycle automation |
Hook |
Optional helper script |
Guaranteed execution at agent lifecycle points; not soft guidance |
| External systems, APIs, databases, browsers |
MCP config |
Optional skill |
Real new capabilities via tools/resources and authenticated external access |
| Everything else |
Out of scope here |
See other customization primitives directly |
Instructions, prompt files, custom agents, and plugin packaging are no longer first-class scope for this skill |
Rules of Thumb
- If it is a reusable multi-step capability with references, scripts, or
assets → skill.
- If it must run deterministically before or after lifecycle events →
hook.
- If it needs real external capabilities, tools, or data outside the
workspace → MCP.
- If a skill depends on external systems, pair the skill with MCP instead of
overloading the skill alone.
- Always choose the smallest sufficient artifact inside this skill's scope.
- Do not use MCP where a local script is enough.
- Do not use a hook for soft guidance when a skill is the real fit.
Always choose the smallest sufficient artifact inside this skill's scope.
Deep Classification Interview
Before generating anything, interview the user with targeted questions. Use
askQuestions when available, and follow the shared ub-authoring
choice-question contract for any multiple-choice prompts. Skip questions whose
answers are already clear from context.
Core Questions (always ask)
- What do you want to build or change? Describe the behavior, workflow,
automation, or integration you need.
- Is this a reusable on-demand workflow, a deterministic lifecycle action,
or an external integration?
- Does it need to run automatically at specific lifecycle points? If yes,
which events matter?
- Does it need access to external systems, APIs, databases, browsers, or
remote data sources?
- Does it need bundled references, scripts, or assets to guide repeated
use?
Conditional Deep-Dive Questions (ask when relevant)
- Which lifecycle events matter? Use the VS Code hook events when a hook
is in scope.
- Which external systems, credentials, transports, or trust boundaries
matter? Use this when MCP is in scope.
- Would a companion artifact materially improve the workflow? Recommend
Skill + MCP when the skill depends on external systems.
After classification, state the recommendation, assumptions, and rationale before generating.
Platform & Research Policy
- Treat the latest stable VS Code and GitHub Copilot customization guidance as
the preferred baseline for artifact choice, file structure, and capability
recommendations.
- Detect workspace and host truth before generating: repository structure,
existing customization artifacts, target host, available tools, and
portability requirements.
- Treat repo and host truth as the gold implementation standard when deciding
what can actually ship safely in the target environment.
- Use web search to verify current official customization guidance against
primary VS Code and GitHub documentation before making non-trivial or
platform-sensitive recommendations.
- If official guidance and repo or host truth diverge materially on a
non-trivial recommendation, surface
OFFICIAL_CONFLICT, implement the
host-safe path, and explain the migration or portability consequence.
- If official sources disagree with each other on a non-trivial
recommendation, also surface
OFFICIAL_CONFLICT instead of silently
collapsing the disagreement.
- If a non-trivial claim cannot be confirmed in official sources after
targeted research, mark it
UNVERIFIED or avoid presenting it as settled
guidance.
- Keep conflict and uncertainty disclosure scoped to non-trivial,
platform-sensitive, or contested guidance rather than simple artifact
generation.
Bundle Recommendations
Many workflows need multiple artifacts working together. Actively recommend these bundles during classification:
| Bundle |
Components |
When to Recommend |
| A |
Skill + MCP |
The workflow is reusable but depends on external systems, authenticated tools, or remote data |
| B |
Hook + helper script |
Deterministic lifecycle automation needs logic that should live outside inline shell |
For detailed bundle guidance and example scenarios, read references/bundles.md.
Generation Workflow
Follow these steps in order:
1. Classify
Parse the request. Identify the artifact type(s) needed using the selection matrix above.
2. Interview
Ask classification questions. Confirm the chosen artifact type(s) with the user.
3. Plan
State assumptions, file tree, and rationale. For the artifact type being generated, load the appropriate reference:
| Artifact Type |
Reference to Load |
| Skills |
references/skills.md |
| Hooks |
references/hooks.md |
| MCP configs |
references/mcp.md |
For customization-artifact writing guidance, read
references/prompt-engineering.md.
For reusable cross-skill authoring conventions, read
../ub-authoring/references/authoring-conventions.md.
Before generating non-trivial or platform-sensitive customizations, compare
official guidance, repo truth, and target host reality and surface
OFFICIAL_CONFLICT or UNVERIFIED when relevant.
4. Generate
Create the files following the loaded reference. Apply these defaults:
- Shared authoring contract: rely on
ub-authoring for reusable naming,
routing, and shared structure conventions.
- Least privilege: expose only necessary tools; minimize dangerous defaults.
- No hardcoded secrets: use MCP
inputs, environment variables, or .env references.
- Concise descriptions: optimize for triggering and discovery, not marketing.
5. Validate
Run the validation checklist from references/validation.md for each generated artifact. Produce:
- Validation checklist (pass/fail per item)
- Smoke-test prompts (how to test the artifact)
- Portability notes (VS Code-only vs Copilot-compatible vs broadly portable)
6. Iterate
Present the output for review. Refine based on user feedback. Re-validate after changes.
Output Contract
Treat this section as the stable output expectation for non-trivial
customization work in this catalog.
Structure every generation response as:
- Recommendation — what to generate and why
- Source truth note — detected host, repo artifact reality, and any
material gap versus latest official guidance
- Assumptions — defaults chosen, unresolved ambiguities
- File tree — directories and files to create or update
- Generated content — file-by-file output
- Validation checklist — human review items + technical checks
- Smoke-test prompts — how to verify the artifact works
- Portability notes — which pieces are VS Code-only, Copilot-compatible, or broadly portable
- Risks / follow-up — preview features, secrets, trust, unsupported host features
- Conflict note when relevant —
OFFICIAL_CONFLICT or UNVERIFIED
with a concise explanation and the implementation consequence
Completion Checklist
- Artifact choice is the smallest sufficient primitive for the request.
- Any recommended multi-artifact bundle is explained and justified.
- Generated files are valid for the chosen customization type.
- Tool access is least-privilege rather than broad by default.
- Validation and smoke-test guidance is explicit.
- VS Code-only versus Agent-Skills-portable behavior is called out.
- Secret handling, trust, or preview-feature risks are surfaced when relevant.
- Any material official-source conflict or unverified non-trivial guidance is
disclosed explicitly when relevant.
Safety Defaults
- Default to read-only planning where possible.
- Default to minimal scopes for generated hooks and MCP servers.
- Never hardcode API keys, tokens, or secrets.
- Gate destructive actions behind approval hooks or confirmation.
- Include review warnings for hooks and MCP configs.
- Warn about trust and security when suggesting third-party skills or MCP servers.
Anti-Patterns to Avoid
- Do NOT default to a skill when a hook or MCP config is the real fit.
- Do NOT treat this skill as the owner of cross-catalog authoring conventions
now that
ub-authoring exists.
- Do NOT generate giant monolithic files — use progressive disclosure and references.
- Do NOT use hooks for soft guidance — hooks are for deterministic lifecycle actions.
- Do NOT use MCP for trivial local tasks — MCP is for real external capabilities.
- Do NOT grant broad tool or secret access by default — use least privilege and explicit inputs.
Freshness Review
- Volatility: high
- Review recommendation: review on touch and during periodic maintenance, targeting a quarterly rhythm when practical.
- Trigger signals: VS Code Copilot skill, hook, or MCP surface changes; Agent Skills spec changes; MCP schema changes; lifecycle-event changes; or portability guidance changes tied to the official Agent Skills spec.
- Enforcement: advisory only; freshness warnings should not block unrelated customization work by default.
- Stable core: smallest-sufficient artifact choice, least privilege, explicit
validation, and the builder-versus-authoring ownership split remain the
durable guidance.
1---2name: ub-customizations3description: Create, update, review, or refactor VS Code Copilot skills, hooks, and MCP configs. Use when the user wants to build or maintain reusable skills, lifecycle hooks, MCP integrations, or the supporting references and validation flow around those artifacts, or needs help deciding between a skill, hook, or MCP config.4---5
6# UB Customizations — VS Code Copilot Customization Builder
7
8## Mission
9
10Route the user to the correct VS Code Copilot artifact within this skill's
11scope, generate safe and valid skills, hooks, or MCP configs, validate output,
12and recommend companion artifacts only when they materially improve the
13workflow.
14
15Implement against the target host and tool reality, but bias the generated
16customization toward current official guidance and forward-compatible artifact
17choices instead of preserving deprecated or legacy customization surfaces by
18default.
19
20## When Not To Use
21
22- Do not use this skill for general repository workflow planning; defer that to
23 `ub-workflow`.
24- Do not use this skill for governance-only policy or evidence questions;
25 defer those to `ub-governance`.
26- Do not use this skill as the owner of reusable cross-skill authoring
27 conventions; defer those to `ub-authoring`.
28- Do not use this skill when the user only needs normal code implementation in
29 an existing stack rather than skill, hook, or MCP artifacts.
30
31## Coordination
32
33- Use `ub-customizations` as the default builder workflow for skills, hooks,
34 and MCP configs.
35- Use `ub-authoring` when the task is about reusable cross-skill conventions
36 such as routing-quality descriptions, non-use boundaries, naming, or shared
37 authoring structure.
38- Use both only when a customization task also changes the shared installable
39 authoring contract.
40
41## Artifact Selection Matrix
42
43Classify the request BEFORE generating anything.
44
45| User Need | Primary Artifact | Common Companions | Why |
46| --- | --- | --- | --- |
47| Reusable multi-step capability with scripts/resources | Skill | Optional MCP config | On-demand domain workflow with bundled references, scripts, or assets |
48| Deterministic lifecycle automation | Hook | Optional helper script | Guaranteed execution at agent lifecycle points; not soft guidance |
49| External systems, APIs, databases, browsers | MCP config | Optional skill | Real new capabilities via tools/resources and authenticated external access |
50| Everything else | Out of scope here | See other customization primitives directly | Instructions, prompt files, custom agents, and plugin packaging are no longer first-class scope for this skill |
51
52## Rules of Thumb
53
541. If it is a **reusable multi-step capability** with references, scripts, or
55 assets → skill.
562. If it must **run deterministically** before or after lifecycle events →
57 hook.
583. If it needs **real external capabilities, tools, or data** outside the
59 workspace → MCP.
604. If a skill depends on external systems, pair the skill with MCP instead of
61 overloading the skill alone.
625. Always choose the smallest sufficient artifact inside this skill's scope.
636. Do not use MCP where a local script is enough.
647. Do not use a hook for soft guidance when a skill is the real fit.
65
66**Always choose the smallest sufficient artifact inside this skill's scope.**
67
68## Deep Classification Interview
69
70Before generating anything, interview the user with targeted questions. Use
71`askQuestions` when available, and follow the shared `ub-authoring`
72choice-question contract for any multiple-choice prompts. Skip questions whose
73answers are already clear from context.
74
75### Core Questions (always ask)
76
771. **What do you want to build or change?** Describe the behavior, workflow,
78 automation, or integration you need.
792. **Is this a reusable on-demand workflow, a deterministic lifecycle action,
80 or an external integration?**
813. **Does it need to run automatically at specific lifecycle points?** If yes,
82 which events matter?
834. **Does it need access to external systems, APIs, databases, browsers, or
84 remote data sources?**
855. **Does it need bundled references, scripts, or assets to guide repeated
86 use?**
87
88### Conditional Deep-Dive Questions (ask when relevant)
89
901. **Which lifecycle events matter?** Use the VS Code hook events when a hook
91 is in scope.
922. **Which external systems, credentials, transports, or trust boundaries
93 matter?** Use this when MCP is in scope.
943. **Would a companion artifact materially improve the workflow?** Recommend
95 Skill + MCP when the skill depends on external systems.
96
97After classification, state the recommendation, assumptions, and rationale before generating.
98
99## Platform & Research Policy
100
101- Treat the latest stable VS Code and GitHub Copilot customization guidance as
102 the preferred baseline for artifact choice, file structure, and capability
103 recommendations.
104- Detect workspace and host truth before generating: repository structure,
105 existing customization artifacts, target host, available tools, and
106 portability requirements.
107- Treat repo and host truth as the gold implementation standard when deciding
108 what can actually ship safely in the target environment.
109- Use web search to verify current official customization guidance against
110 primary VS Code and GitHub documentation before making non-trivial or
111 platform-sensitive recommendations.
112- If official guidance and repo or host truth diverge materially on a
113 non-trivial recommendation, surface `OFFICIAL_CONFLICT`, implement the
114 host-safe path, and explain the migration or portability consequence.
115- If official sources disagree with each other on a non-trivial
116 recommendation, also surface `OFFICIAL_CONFLICT` instead of silently
117 collapsing the disagreement.
118- If a non-trivial claim cannot be confirmed in official sources after
119 targeted research, mark it `UNVERIFIED` or avoid presenting it as settled
120 guidance.
121- Keep conflict and uncertainty disclosure scoped to non-trivial,
122 platform-sensitive, or contested guidance rather than simple artifact
123 generation.
124
125## Bundle Recommendations
126
127Many workflows need multiple artifacts working together. Actively recommend these bundles during classification:
128
129| Bundle | Components | When to Recommend |
130| --- | --- | --- |
131| **A** | Skill + MCP | The workflow is reusable but depends on external systems, authenticated tools, or remote data |
132| **B** | Hook + helper script | Deterministic lifecycle automation needs logic that should live outside inline shell |
133
134For detailed bundle guidance and example scenarios, read [references/bundles.md](references/bundles.md).
135
136## Generation Workflow
137
138Follow these steps in order:
139
140### 1. Classify
141
142Parse the request. Identify the artifact type(s) needed using the selection matrix above.
143
144### 2. Interview
145
146Ask classification questions. Confirm the chosen artifact type(s) with the user.
147
148### 3. Plan
149
150State assumptions, file tree, and rationale. For the artifact type being generated, load the appropriate reference:
151
152| Artifact Type | Reference to Load |
153| --- | --- |
154| Skills | [references/skills.md](references/skills.md) |
155| Hooks | [references/hooks.md](references/hooks.md) |
156| MCP configs | [references/mcp.md](references/mcp.md) |
157
158For customization-artifact writing guidance, read
159[references/prompt-engineering.md](references/prompt-engineering.md).
160For reusable cross-skill authoring conventions, read
161[`../ub-authoring/references/authoring-conventions.md`](../ub-authoring/references/authoring-conventions.md).
162
163Before generating non-trivial or platform-sensitive customizations, compare
164official guidance, repo truth, and target host reality and surface
165`OFFICIAL_CONFLICT` or `UNVERIFIED` when relevant.
166
167### 4. Generate
168
169Create the files following the loaded reference. Apply these defaults:
170
171- **Shared authoring contract**: rely on `ub-authoring` for reusable naming,
172 routing, and shared structure conventions.
173- **Least privilege**: expose only necessary tools; minimize dangerous defaults.
174- **No hardcoded secrets**: use MCP `inputs`, environment variables, or `.env` references.
175- **Concise descriptions**: optimize for triggering and discovery, not marketing.
176
177### 5. Validate
178
179Run the validation checklist from [references/validation.md](references/validation.md) for each generated artifact. Produce:
180
181- Validation checklist (pass/fail per item)
182- Smoke-test prompts (how to test the artifact)
183- Portability notes (VS Code-only vs Copilot-compatible vs broadly portable)
184
185### 6. Iterate
186
187Present the output for review. Refine based on user feedback. Re-validate after changes.
188
189## Output Contract
190
191Treat this section as the stable output expectation for non-trivial
192customization work in this catalog.
193
194Structure every generation response as:
195
1961. **Recommendation** — what to generate and why
1972. **Source truth note** — detected host, repo artifact reality, and any
198 material gap versus latest official guidance
1993. **Assumptions** — defaults chosen, unresolved ambiguities
2004. **File tree** — directories and files to create or update
2015. **Generated content** — file-by-file output
2026. **Validation checklist** — human review items + technical checks
2037. **Smoke-test prompts** — how to verify the artifact works
2048. **Portability notes** — which pieces are VS Code-only, Copilot-compatible, or broadly portable
2059. **Risks / follow-up** — preview features, secrets, trust, unsupported host features
20610. **Conflict note when relevant** — `OFFICIAL_CONFLICT` or `UNVERIFIED`
207 with a concise explanation and the implementation consequence
208
209## Completion Checklist
210
211- Artifact choice is the smallest sufficient primitive for the request.
212- Any recommended multi-artifact bundle is explained and justified.
213- Generated files are valid for the chosen customization type.
214- Tool access is least-privilege rather than broad by default.
215- Validation and smoke-test guidance is explicit.
216- VS Code-only versus Agent-Skills-portable behavior is called out.
217- Secret handling, trust, or preview-feature risks are surfaced when relevant.
218- Any material official-source conflict or unverified non-trivial guidance is
219 disclosed explicitly when relevant.
220
221## Safety Defaults
222
223- Default to **read-only planning** where possible.
224- Default to **minimal scopes** for generated hooks and MCP servers.
225- **Never hardcode** API keys, tokens, or secrets.
226- Gate destructive actions behind **approval hooks** or confirmation.
227- Include **review warnings** for hooks and MCP configs.
228- Warn about **trust and security** when suggesting third-party skills or MCP servers.
229
230## Anti-Patterns to Avoid
231
232- Do NOT default to a skill when a hook or MCP config is the real fit.
233- Do NOT treat this skill as the owner of cross-catalog authoring conventions
234 now that `ub-authoring` exists.
235- Do NOT generate giant monolithic files — use progressive disclosure and references.
236- Do NOT use hooks for soft guidance — hooks are for deterministic lifecycle actions.
237- Do NOT use MCP for trivial local tasks — MCP is for real external capabilities.
238- Do NOT grant broad tool or secret access by default — use least privilege and explicit inputs.
239
240## Freshness Review
241
242- Volatility: high
243- Review recommendation: review on touch and during periodic maintenance, targeting a quarterly rhythm when practical.
244- Trigger signals: VS Code Copilot skill, hook, or MCP surface changes; Agent Skills spec changes; MCP schema changes; lifecycle-event changes; or portability guidance changes tied to the official Agent Skills spec.
245- Enforcement: advisory only; freshness warnings should not block unrelated customization work by default.
246- Stable core: smallest-sufficient artifact choice, least privilege, explicit
247 validation, and the builder-versus-authoring ownership split remain the
248 durable guidance.