tsdown
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill consists of documentation and configuration examples for the
tsdownlibrary bundler. Manual review of all files reveals no malicious instructions, prompt injections, or unauthorized data access. The content is educational and instructional for developers using the tool. - [EXTERNAL_DOWNLOADS]: The skill references legitimate ecosystem packages such as
tsdown,@tsdown/css, androlldown-plugin-wasmfrom trusted registries. These are standard dependencies for the mentioned bundling tasks and originate from known vendors in the JavaScript ecosystem. - [COMMAND_EXECUTION]: The documentation includes standard CLI commands for library development, such as
npx tsdownandnpx tsdown-migrate, which are intended for user-initiated builds and migrations. These commands are part of the documented tool's core functionality. - [METADATA_POISONING]: Automated scanners flagged
README.md,SKILL.md, andreferences/guide-migrate-from-tsup.mdas potentially malicious. A manual technical review confirms these files contain only standard Markdown documentation and code snippets for a legitimate library bundler. The automated alerts are concluded to be false positives based on the context of thetsdownproject and its author.
Recommendations
- CRITICAL: 3 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata