allow-bun

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose, but it materially weakens execution safeguards by pre-approving shell commands and inline eval. Bun provenance is legitimate, yet `bunx`/package execution introduces medium supply-chain risk from npm; overall this is risky autonomy expansion rather than confirmed malware.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Sep 8, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/kizuna-inc%2Fkz-skill%2Fallow-bun%2F@348c282caede9bd4d6f18be5d5988528976b848c2b38b0e37b5ee84739e388de
Security Audit — socket — allow-bun