bun-toolchain

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user to configure shell execution through lefthook and Bun.$. These are standard features of the described toolchain intended for running linters and formatters on source code.
  • [EXTERNAL_DOWNLOADS]: The skill references standard GitHub Actions (actions/checkout, oven-sh/setup-bun) and ecosystem packages (oxlint, oxfmt, lefthook). The oven-sh organization is the official provider for Bun. All referenced external resources are well-known services or official repositories.
  • [REMOTE_CODE_EXECUTION]: The configuration for lefthook.yml includes shell commands (bunx --no-install oxlint) that run on staged files. This is standard behavior for git hook managers and does not involve downloading and piping unknown scripts to the shell.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 12:10 AM
Security Audit — agent-trust-hub — bun-toolchain