Back to skill

Security audit

Bun Scripts

Security checks for vulnerabilities and agentic risk

Overview

This skill teaches an agent to use Bun for scripting and development tasks; its capabilities are disclosed, but users should supervise package installs, shell commands, network requests, and file writes.

Install this only if you want the agent to prefer Bun for TypeScript/JavaScript scripting. Review any proposed bun add, bunx, shell command, network fetch, file write, or server start before it runs, especially in projects with existing Node/npm workflows or sensitive environment variables.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:164
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:164-169; additional occurrences at SKILL.md:25, SKILL.md:44, and references/REFERENCE.md:323
Vulnerability Type: Insecure third-party dependency execution
Risk Level: Medium

bash
bun add zod                    # runtime dependency
bun add -d @types/node         # dev dependency
bun remove unused-pkg          # remove
bunx prettier --write .        # run without installing

Technical Analysis

The Skill broadly recommends installing dependencies through bun add and executing registry packages through bunx without requiring exact versions, lockfile verification, package provenance checks, or explicit user approval.

In particular, bunx can download and execute package-controlled code in the current project context. An unpinned package name may resolve to a subsequently compromised release, while a misspelled or attacker-influenced name may resolve to a typosquatted or dependency-confusion package. Such package code can inherit the agent process's filesystem, environment, subprocess, and network access.

The documentation also notes Bun's automatic package installation behavior. Although this is legitimate Bun functionality, relying on automatic or ephemeral dependency resolution weakens reproducibility and expands the supply-chain attack surface beyond the minimum privileges needed for tasks that can be completed with Bun's built-in APIs.

Attack Path

  1. An attacker influences a package name through user-controlled instructions, repository content, or a typo resembling a legitimate package.
  2. The agent follows the Skill's general recommendation to invoke bunx <pkg> or bun add <pkg>.
  3. Bun resolves and downloads the package from the configured registry without a mandatory pinned version or provenance validation.
  4. The downloaded package's executable or package-controlled code runs in the project context.
  5. Malicious c ...[truncated 962 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit user approval before installing or executing any third-party package.
  • Use verified package names and pin exact versions, including versions passed to bunx.
  • Prefer committed and reviewed lockfiles, and use bun ci or an equivalent frozen-lockfile workflow in automated environments.
  • Validate package provenance, publisher identity, integrity metadata, and registry source before execution.
  • Avoid constructing package names from untrusted user input or repository-controlled instructions.
  • Prefer Bun's built-in functionality when it can satisfy the task without introducing a dependency.
  • Run unavoidable third-party tools in a restricted environment with minimal filesystem access, sanitized environment variables, limited subprocess permissions, and constrained outbound network access.
  • Document that ephemeral execution does not imply safety and that bunx packages execute with the invoking process's permissions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
1. Start with [references/REFERENCE.md](references/REFERENCE.md) — offline, curated, covers the

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 274)May include surrounding context.

md
1. Start with [references/REFERENCE.md](references/REFERENCE.md) — offline, curated, covers the

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use this skill whenever the agent needs to create, run, or manage scripts and CLI tools, which is a very broad class of common tasks. Although Bun-specific keywords are listed afterward, the preceding activation guidance lacks clear boundaries or exclusion conditions, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The claim that Bun.$ has 'no command injection risk' is overly absolute and can mislead an agent into treating shell execution as categorically safe. While interpolation escaping helps, shell pipelines, unsafe command composition, trusted-command assumptions, and other shell semantics can still create dangerous behavior or enable misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example performs an external network fetch and writes the response to a local file without any warning that it accesses remote data and modifies the filesystem. In an agent setting, examples can become default behavior, increasing the risk of silent data transfer, unexpected file creation, or use of untrusted remote content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

typescript
// fetch-data.ts
const resp = await fetch("https://api.example.com/data");
const data: Record<string, unknown> = await resp.json();
await Bun.write("output.json", JSON.stringify(data, null, 2));
console.log(`Wrote ${Bun.file("output.json").size} bytes`);

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a skill for writing, running, and managing TypeScript scripts and CLI tools with Bun. However, the documentation also instructs the agent to build HTTP servers with Bun.serve and to fetch remote documentation and API data, which broadens the skill into network service and external network access behaviors beyond the core scripting/CLI scope claimed in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.