bun-validator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/validate.py script executes the command bun --version using subprocess.run to check the environment. This is a standard and safe practice for a validation tool as it uses a hardcoded command without external input interpolation.\n- [EXTERNAL_DOWNLOADS]: The skill's validation report suggests a remote installation command (curl -fsSL https://bun.sh/install | bash) to the user if Bun is missing. This targets the official and well-known installation source for the Bun runtime. The skill does not execute this command itself; it is provided as a suggested remediation step in the report text.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests package.json files from the monorepo structure, which is a potential surface for indirect prompt injection. However, the risk is minimized because the script uses structured JSON parsing and only evaluates specific metadata fields.\n
  • Ingestion points: package.json files in the project root and workspace subdirectories (processed in scripts/validate.py).\n
  • Boundary markers: None explicitly defined in the prompt, but logic is restricted to JSON keys.\n
  • Capability inventory: The script is limited to reading files, checking the Bun version via subprocess, and printing reports to stdout.\n
  • Sanitization: Content is strictly parsed via the standard json module before any values are evaluated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — bun-validator