bun-toolchain
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user to configure shell execution through
lefthookandBun.$. These are standard features of the described toolchain intended for running linters and formatters on source code. - [EXTERNAL_DOWNLOADS]: The skill references standard GitHub Actions (
actions/checkout,oven-sh/setup-bun) and ecosystem packages (oxlint,oxfmt,lefthook). Theoven-shorganization is the official provider for Bun. All referenced external resources are well-known services or official repositories. - [REMOTE_CODE_EXECUTION]: The configuration for
lefthook.ymlincludes shell commands (bunx --no-install oxlint) that run on staged files. This is standard behavior for git hook managers and does not involve downloading and piping unknown scripts to the shell.
Audit Metadata