bun-development

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is a Bun development skill / documentation that is consistent with its stated purpose. It contains standard developer guidance (installing Bun, creating projects, using Bun APIs). The primary security concern is the inclusion of direct download-and-execute installer commands (curl | bash and PowerShell irm | iex) and unpinned git installs; these are legitimate convenience instructions but are high-risk supply-chain patterns because remote content executes on users' machines. No explicit credential harvesting, obfuscated malware, or exfiltration is present in the document itself. Recommend treating installer commands as risky: prefer verified installers, checksums/signatures, pinned releases, and caution when installing from arbitrary git URLs or running global installs.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fbun-development%2F@8eaeeb88a1c9d962b35c47bd1e2cb2fd78a220ef