Bun Scripts

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Bun scripting helper with broad preferences, but its capabilities are disclosed and fit its stated purpose.

Install this if you want agents to favor Bun for local JavaScript and TypeScript scripting. Review agent-proposed commands in sensitive repositories, especially package installs, shell commands, server startup, network fetches, and scripts that may read .env files or local project data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger guidance is extremely broad, causing this skill to activate for many generic JavaScript, package-manager, testing, and scripting requests. Over-broad activation can steer the agent into using Bun-specific behaviors and capabilities in contexts where they were not requested, increasing the chance of unintended tool use or risky operations.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill explicitly tells the agent to prefer Bun over alternatives the user names unless the user 'explicitly insists,' which can override user intent and lead to unauthorized tool substitution. In security-sensitive environments, silently changing runtimes or package managers can alter execution semantics, dependency behavior, and trust assumptions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal