Fähigkeiten bun-development
📦

bun-development

Inhaltsrevision r1 Kritisch ⚙️ Externe Befehle🌐 Netzwerkzugriff📁 Dateisystemzugriff🔑 Umgebungsvariablen

Bun JavaScript プロジェクトをより速く構築

Bun は JavaScript と TypeScript のツール環境を簡素化できますが、チームが移行する前には明確なワークフローが必要です。このスキルは、セットアップ、パッケージ、テスト、バンドル、ランタイム API、Node.js 移行に関する実践的なガイダンスを提供します。

Unterstützt: Claude Codex Code(CC)
⚠️ 38 Schlecht

Dieser Skill ist Teil eines Skill-Pakets

Installieren Sie das gesamte Skill-Paket, um mit einem Befehl alle Skills zu erhalten, die die Aufgabe braucht.

Mit meinem Agent installieren

Kopieren Sie diese Anfrage in Ihren Agent. Sie enthält die maßgebliche Skill-Seite und das Manifest.

Agent-Anfrage
Review the Skillstore skill "bun-development" from https://skillstore.io/skills/sickn33-bun-development.md and its manifest at https://skillstore.io/api/skills/sickn33-bun-development/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Ihr Agent sollte weiterhin seinen Plan anzeigen und alle von der Sicherheitsrichtlinie verlangten Bestätigungen anfordern.

Agent-lesbare Ressourcen

Verwenden Sie diese Links, wenn ein KI-Agent, Crawler oder Skript sauberen Kontext benötigt, statt die vollständige Seite zu lesen.

Testen

„bun-development“ wird verwendet. TypeScript API 用の Bun スタータープロジェクトが必要です。

Erwartetes Ergebnis:

推奨スクリプト、依存関係コマンド、ランタイム選択、最初のテスト計画を含むプロジェクトセットアップ手順。

„bun-development“ wird verwendet. Node.js サービスを Bun に移行したいです。

Erwartetes Ergebnis:

スクリプト、パッケージマネージャーの置き換え、互換性問題、Bun ネイティブ API、検証手順を扱う移行チェックリスト。

„bun-development“ wird verwendet. 本番環境向けに Bun CLI をバンドルする必要があります。

Erwartetes Ergebnis:

ターゲット選択、圧縮、ソースマップ、実行可能出力、アセット処理の注意点を含むビルド計画。

Sicherheitsaudit

Kritisch
v4 • 6.7.2026 Versionsbericht öffnen

The audit found no prompt-injection content or hidden data-exfiltration intent in SKILL.md. Most static hits are Markdown fences, sample Bun server handlers, environment variable examples, or documentation links. Confirmed risks are pipe-to-shell install commands and a non-default npm registry example.

1
Gescannte Dateien
692
Analysierte Zeilen
4
Prüfelemente
0
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (3)

Kritisch
Pipe to shell pattern
curl -fsSL https://bun.sh/install | bash
The command pipes a remote install script directly into bash. This is a real remote code execution risk if the network, script, or source is compromised.
Kritisch
Pipe to shell pattern
curl -fsSL https://bun.sh/install | bash
The command pipes a remote install script directly into bash. This is a real remote code execution risk if the network, script, or source is compromised.
Hoch
Non-standard NPM registry
bun add lodash --registry https://registry.npmmirror.com
The example installs from registry.npmmirror.com instead of the default npm registry. Changing registries can introduce dependency confusion and supply-chain trust risk.
Elemente der Fähigkeitsprüfung (4)

Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.

Hoch
PowerShell invocation
powershell -c "irm bun.sh/install.ps1 | iex"
The Windows install example invokes PowerShell and executes a remote install script through iex. This can run unreviewed code on the user system.
Hoch
Hardcoded URL
bun add lodash --registry https://registry.npmmirror.com
The URL selects a third-party npm mirror with --registry, changing package trust boundaries. This is a real supply-chain exposure even though shown as an example.
Niedrig
Hardcoded URL
curl -fsSL https://bun.sh/install | bash
The URL is used in a curl pipe-to-shell install command, which downloads remote code for execution. The official source lowers malicious intent but not remote execution risk.
Niedrig
Hardcoded URL
curl -fsSL https://bun.sh/install | bash
The URL is used in a curl pipe-to-shell install command, which downloads remote code for execution. The official source lowers malicious intent but not remote execution risk.

Risikofaktoren

⚙️ Externe Befehle (74)
🌐 Netzwerkzugriff (13)
📁 Dateisystemzugriff (1)
🔑 Umgebungsvariablen (9)

Erkannte Muster

Pipe to shell pattern×2Non-standard NPM registry
Geprüft von: codex Audit-Verlauf anzeigen →
Diesen Bericht teilen & zitieren

Teile den versionierten Bewertungsbericht, das neutrale Badge, die Einbettungskarte und Zitate. Skillstore berichtet Nachweise, ohne zu entscheiden, ob dieser Skill sicher ist.

Versionsbericht öffnen
Sicherheitsbewertung

Berichtslink kopieren

https://skillstore.io/skills/sickn33-bun-development/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown-Badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/sickn33-bun-development/security.svg)](https://skillstore.io/skills/sickn33-bun-development?utm_source=security_passport_badge)

HTML-Badge

<a href="https://skillstore.io/skills/sickn33-bun-development?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-bun-development/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Einbettungskarte

<iframe src="https://skillstore.io/embed/skills/sickn33-bun-development.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Wissenschaftliche Zitate (APA · BibTeX · CFF)

APA-Zitat

sickn33. (2026). bun-development security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-bun-development/audits/4

BibTeX-Zitat

@techreport{sickn33-sickn33-bun-development-2026, author = {sickn33}, title = {bun-development security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/sickn33-bun-development/audits/4}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "bun-development security audit report (audit version 4)" version: "unspecified" type: report authors: - name: "sickn33" date-released: "2026-07-06" url: "https://skillstore.io/skills/sickn33-bun-development/audits/4" identifiers: - type: other value: "skillstore:sickn33-bun-development:audit:4" description: "Skillstore immutable audit report identifier"

Skillstore-Score

Warum dieser Score Evidenzvertrauen: Mittel
55
Architektur
85
Wartbarkeit
87
Inhalt
70
Gemeinschaft
78
Spezifikationskonformität

Was Sie erstellen können

Bun フロントエンドプロジェクトを始める

TypeScript のデフォルト設定と高速なパッケージワークフローを備えた、Bun ベースの React、Vite、Next.js プロジェクトをセットアップします。

Bun サービスをプロトタイプする

ネイティブランタイム API を使って、Bun の HTTP、WebSocket、SQLite、パスワードハッシュ化のプロトタイプを構築します。

Node.js 移行を計画する

移行前に、スクリプト、パッケージ管理、テスト、互換性チェック、Bun ネイティブの代替手段を整理します。

Diese Prompts ausprobieren

Bun プロジェクトを始める
新しい Bun TypeScript プロジェクトの作成を手伝ってください。セットアップ手順、基本的なスクリプト、最初のテストコマンドを含めてください。
Node.js スクリプトを移行する
私の Node.js パッケージワークフローをレビューし、スクリプト、依存関係、テスト、ロックファイルに関する Bun 移行計画を提案してください。
ランタイム API を最適化する
この Bun サービス設計を監査し、ファイル処理、HTTP ルーティング、WebSocket、SQLite、パスワードハッシュ化に適したネイティブ API を推奨してください。
本番ビルドを準備する
バンドル、実行可能ターゲット、ソースマップ、環境ファイル、デプロイリスクを扱う、本番向け Bun ビルドチェックリストを作成してください。

Bewährte Praktiken

  • リモートインストールスクリプトを実行する前に、特に pipe-to-shell コマンドの場合は内容を検証してください。
  • 再現可能な依存関係インストールのために、パッケージバージョンを固定し、信頼できるレジストリを使用してください。
  • ランタイム、バンドラー、移行設定を変更した後は、Bun テストとビルドチェックを実行してください。

Vermeiden

  • 確認やチェックサム検証を行わずに、リモートスクリプトを直接シェルへパイプすること。
  • 信頼性、可用性、パッケージの整合性を確認せずに npm レジストリをグローバルに切り替えること。
  • エッジケースをテストせず、すべての Node.js API が Bun 上で同じように動作すると想定すること。

Häufig gestellte Fragen

このスキルは Bun を自動的にインストールしますか?
いいえ。コマンド例とガイダンスを提供します。どのコマンドを実行するかはユーザーが判断します。
JavaScript と TypeScript の両方をサポートしていますか?
はい。JavaScript、TypeScript、JSX、テスト、バンドルの Bun ワークフローに焦点を当てています。
Node.js からの移行を支援できますか?
はい。スクリプトの置き換え、パッケージマネージャーの変更、互換性チェック、Bun 固有の代替手段を扱います。
サーバー開発も扱っていますか?
はい。Bun.serve HTTP ハンドラー、WebSocket の例、SQLite の使用、パスワードハッシュ化のパターンを含みます。
インストールコマンドにリスクはありませんか?
いいえ。リモートインストールスクリプトやレジストリ変更は、実行前に信頼性確認が必要です。
公式の Bun ドキュメントの代わりになりますか?
いいえ。バージョン固有の挙動やリリース変更については、公式ドキュメントを使用してください。

Entwicklerdetails

Autor

sickn33

Lizenz

MIT

Skillstore-Revision

r1

Versionshinweis

Der Autor hat keine Version angegeben.

Ref.

01171b582d636c013315c5e0d969c64f8d9cdff2

Aktualität der Wartung

20.7.2026

Nutzung

11 Downloads · 206 Aufrufe

Dateistruktur

📄 SKILL.md

Mehr von sickn33

Alle anzeigen
📦

senior-fullstack

81

シニアレベルのパターンでフルスタックアプリを構築

チームには、モダンなWebアプリケーション向けに一貫したセットアップ、アーキテクチャ、レビュー指針が必要です。このスキルは、React、Next.js、Node.js、GraphQL、PostgreSQLプロジェクト向けのスキャフォールダー、ワークフローのリファレンス、品質向上のためのプロンプトを提供します。

Programmierung & Entwicklung Ansehen
Alle anzeigen
📦

testing-patterns

81

コードベース全体で信頼性の高いテストを計画する

von 0xDarkMatter

このスキルは、テスト範囲を混在させずに、チームがテスト戦略、モック、データフィクスチャ、カバレッジゲート、CIパターンを選択するのに役立ちます。Claude、Codex、Claude Codeに、ユニット、統合、エンドツーエンド、TDD、パイプラインテストのための構造化されたガイダンスを提供します。

Programmierung & Entwicklung Ansehen