duskmoon-bundler
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of Elixir dependencies (duskmoon_bundler, duskmoon_bundler_runtime) from Hex and various JavaScript packages (lodash, eslint) via NPM registries.
- [COMMAND_EXECUTION]: It uses Mix-based commands to execute asset build pipelines, development servers, and local package binaries, which are standard for Phoenix development environments.
- [SAFE]: No malicious behavior, obfuscation, or data exfiltration patterns were identified. The toolchain explicitly addresses supply-chain security by preventing the automatic execution of NPM lifecycle hooks and providing warnings for packages that use them.
Audit Metadata