bun-package-manager

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides standard documentation for the Bun package manager. All commands (bun install, bun add, bun update, etc.) are standard CLI usages.
  • [SAFE]: References to external sources like GitHub (git@github.com:user/repo.git) are provided as syntax examples for installing packages from git repositories.
  • [SAFE]: Instructions for setting authentication tokens for private registries use valid placeholder patterns (YOUR_TOKEN) and follow standard security practices for tool configuration.
  • [SAFE]: The use of bun pm trust is a legitimate Bun feature for managing lifecycle scripts of specific packages, and the skill correctly warns against mixing package managers or committing node_modules.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:49 AM
Security Audit — agent-trust-hub — bun-package-manager