Bun Shell

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] Benign: The code fragment is a coherent, legitimate documentation/example set for Bun Shell usage. It aligns with the stated purpose, uses standard Bun APIs, and shows typical shell automation patterns without introducing suspicious data flows or credential handling. LLM verification: The provided file is documentation for Bun's shell and spawn APIs and contains no explicit malware, obfuscated payloads, or hardcoded secrets. However, it documents powerful primitives that enable arbitrary command execution, environment exposure, filesystem reads, and network operations. These capabilities are high-risk in a supply-chain or automation-agent context if inputs are untrusted or permissions are broad. Treat integration of this skill as sensitive: enforce sandboxing, input sanitizat

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fbun-shell%2F@478d37e8d0194cc11f4a2d190ddf95a8f56c0724