skills/antfu/skills/tsdown/Gen Agent Trust Hub

tsdown

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill consists of documentation and configuration examples for the tsdown library bundler. Manual review of all files reveals no malicious instructions, prompt injections, or unauthorized data access. The content is educational and instructional for developers using the tool.
  • [EXTERNAL_DOWNLOADS]: The skill references legitimate ecosystem packages such as tsdown, @tsdown/css, and rolldown-plugin-wasm from trusted registries. These are standard dependencies for the mentioned bundling tasks and originate from known vendors in the JavaScript ecosystem.
  • [COMMAND_EXECUTION]: The documentation includes standard CLI commands for library development, such as npx tsdown and npx tsdown-migrate, which are intended for user-initiated builds and migrations. These commands are part of the documented tool's core functionality.
  • [METADATA_POISONING]: Automated scanners flagged README.md, SKILL.md, and references/guide-migrate-from-tsup.md as potentially malicious. A manual technical review confirms these files contain only standard Markdown documentation and code snippets for a legitimate library bundler. The automated alerts are concluded to be false positives based on the context of the tsdown project and its author.
Recommendations
  • CRITICAL: 3 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 07:43 AM
Security Audit — agent-trust-hub — tsdown