bunjs-docker-mastery

Fail

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE] (SAFE): Comprehensive analysis of the 19 files shows that the skill follows modern security and architecture standards for backend development.\n- [EXTERNAL_DOWNLOADS] (SAFE): The skill specifies installation of standard, well-known libraries (such as Hono, Zod, and Drizzle) from the official npm registry using the Bun package manager.\n- [DATA_EXFILTRATION] (SAFE): A structured logger is configured using Pino, which includes a specific redaction policy to prevent sensitive information like passwords, tokens, and authorization headers from being written to logs.\n- [COMMAND_EXECUTION] (SAFE): Shell scripts and Docker instructions are strictly limited to project scaffolding, initialization, and container management within development and production contexts.\n- [PROMPT_INJECTION] (SAFE): The instructional content focuses on technical assistance and clean code principles without attempting to override agent safety protocols or system prompts.\n- [MALICIOUS_URLS] (SAFE): The automated scanner alert for 'logger.info' is a confirmed false positive; technical review of the code confirms this is a standard application logging call and not a reference to a malicious domain.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 17, 2026, 06:07 PM