bun-validator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/validate.pyscript executes the commandbun --versionusingsubprocess.runto check the environment. This is a standard and safe practice for a validation tool as it uses a hardcoded command without external input interpolation.\n- [EXTERNAL_DOWNLOADS]: The skill's validation report suggests a remote installation command (curl -fsSL https://bun.sh/install | bash) to the user if Bun is missing. This targets the official and well-known installation source for the Bun runtime. The skill does not execute this command itself; it is provided as a suggested remediation step in the report text.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingestspackage.jsonfiles from the monorepo structure, which is a potential surface for indirect prompt injection. However, the risk is minimized because the script uses structured JSON parsing and only evaluates specific metadata fields.\n - Ingestion points:
package.jsonfiles in the project root and workspace subdirectories (processed inscripts/validate.py).\n - Boundary markers: None explicitly defined in the prompt, but logic is restricted to JSON keys.\n
- Capability inventory: The script is limited to reading files, checking the Bun version via subprocess, and printing reports to stdout.\n
- Sanitization: Content is strictly parsed via the standard
jsonmodule before any values are evaluated.
Audit Metadata