bunjs-docker-mastery
Fail
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: CRITICAL
Full Analysis
- [SAFE] (SAFE): Comprehensive analysis of the 19 files shows that the skill follows modern security and architecture standards for backend development.\n- [EXTERNAL_DOWNLOADS] (SAFE): The skill specifies installation of standard, well-known libraries (such as Hono, Zod, and Drizzle) from the official npm registry using the Bun package manager.\n- [DATA_EXFILTRATION] (SAFE): A structured logger is configured using Pino, which includes a specific redaction policy to prevent sensitive information like passwords, tokens, and authorization headers from being written to logs.\n- [COMMAND_EXECUTION] (SAFE): Shell scripts and Docker instructions are strictly limited to project scaffolding, initialization, and container management within development and production contexts.\n- [PROMPT_INJECTION] (SAFE): The instructional content focuses on technical assistance and clean code principles without attempting to override agent safety protocols or system prompts.\n- [MALICIOUS_URLS] (SAFE): The automated scanner alert for 'logger.info' is a confirmed false positive; technical review of the code confirms this is a standard application logging call and not a reference to a malicious domain.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata