Agent skill

Bun Runtime Best Practices

by shepherdjerred in shepherdjerred/monorepo

Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment.

GPL-3.0Auto-check passedDevelopment

Install Bun Runtime Best Practices

skills CLI
$ npx skills add shepherdjerred/monorepo --skill bun-runtime-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shepherdjerred/monorepo bun-runtime-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shepherdjerred/monorepo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/dotfiles/dot_agents/skills/bun-runtime-best-practices .claude/skills/bun-runtime-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bun-runtime-best-practices
GitHub stars
112
Token cost
~2k tokens
SKILL.md length
825 words
Files
4 (incl. references)
Skills in repo
63
Repo updated
First seen
Licence
GPL-3.0

At a glance

Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment.

  • Reviewing Bun-only TypeScript
  • SKILL.md covers Current baseline, Choose the narrowest correct API, Validate system boundaries and Files and paths, plus 7 more sections
  • Calls bun and sh
  • Selecting Bun versus Web

What it does

Bun Runtime Best Practices is an agent skill from shepherdjerred/monorepo. Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment. Use when writing or reviewing Bun-only TypeScript, selecting Bun versus Web or Node APIs, or migrating Node code to Bun.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/data-networking.md`, `references/io-process-modules.md` and `references/release-notes-1.3.md`).

It sits in Development. It works with Bun and TypeScript. The repository describes itself as: Monorepo for all of my projects. The licence is GPL-3.0.

When your agent uses it

  • Reviewing Bun-only TypeScript
  • Selecting Bun versus Web
  • Migrating Node code to Bun

Example prompts

  • “/bun-runtime-best-practices”

What it can do on your machine

Read from SKILL.md and the folder at commit da14ae9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bun Runtime Best Practices loads about 2k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 69 tokens; SKILL.md has 825 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shepherdjerred/monorepo at commit da14ae9, republished under its GPL-3.0 licence (© shepherdjerred). 825 words, ~2,026 tokens.

Download SKILL.mdSave it as .claude/skills/bun-runtime-best-practices/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
bun-runtime-best-practices
description
Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment. Use when writing or reviewing Bun-only TypeScript, selecting Bun versus Web or Node APIs, or migrating Node code to Bun.

Bun Runtime Best Practices

Use Bun APIs when they provide a clear Bun-native capability. Use standard Web APIs for portability and node: APIs when Bun does not cover the operation or the code must remain Node-compatible. Do not replace a correct portable API merely because a Bun equivalent exists.

Current baseline

Verified against Bun 1.3.14 on 2026-08-03. Check the project pin and runtime before relying on a newly added API:

bash
bun --version

Bun 1.3.14 adds Bun.Image, faster isolated-linker warm installs, and experimental HTTP/2 and HTTP/3 server support. Features explicitly marked experimental in Bun's documentation are not stable defaults.

Read references/release-notes-1.3.md when upgrading Bun or evaluating a new 1.3 API. Read references/io-process-modules.md for detailed file, subprocess, shell, environment, module, stream, binary, hashing, and worker patterns. Read references/data-networking.md for HTTP, WebSocket, SQL, Redis, SQLite, S3, cookies, CSRF, secrets, and cron guidance.

Choose the narrowest correct API

NeedDefaultWhy
Read or write a whole fileBun.file() / Bun.write()Concise Bun-native blob and sink APIs
Directory traversal, permissions, links, metadata mutationnode:fs/promisesBun documents Node file APIs for uncovered operations
Portable HTTP, streams, binary dataWeb APIsfetch, Request, Response, streams, and typed arrays work across runtimes
Spawn a program with known argumentsBun.spawn()Literal argv avoids shell parsing
Cross-platform shell pipelineBun ShellSupports pipelines and escapes interpolated strings
Path manipulationnode:pathHandles separators and normalization correctly
Password hashingBun.passwordArgon2 and bcrypt password-specific API
General cryptographyWeb Crypto or node:cryptoRequired for cryptographic hashes, signatures, ciphers, and key operations
Non-cryptographic hashingBun.hashFast checksums and hash tables; never passwords or signatures

Validate system boundaries

Environment variables, request bodies, database results, Redis values, and file JSON are untrusted input. Parse them before assigning domain types.

typescript
import { z } from "zod";

const Environment = z.object({
  DATABASE_URL: z.string().url(),
  PORT: z.coerce.number().int().min(1).max(65_535).default(3000),
});

const environment = Environment.parse(Bun.env);

Bun.env, process.env, and import.meta.env expose the same environment. Bun.env does not make arbitrary variables statically safe; schema validation does.

Files and paths

Bun.file("relative/path") resolves relative to the process working directory, not the current source file. Anchor source-relative resources explicitly.

typescript
import { join } from "node:path";
import { z } from "zod";

const Config = z.object({
  name: z.string(),
  retries: z.number().int().min(0),
});

const configPath = join(import.meta.dir, "config.json");
const config = Config.parse(await Bun.file(configPath).json());
await Bun.write(join(import.meta.dir, "generated", "output.json"), JSON.stringify(config), {
  createPath: true,
});

Use node:fs/promises for directory and metadata operations that Bun.file and Bun.write do not model.

Subprocesses

Prefer literal argv. Capture stderr and enforce the exit status before consuming output as successful.

typescript
const process = Bun.spawn(["git", "status", "--short"], {
  cwd: import.meta.dir,
  stdout: "pipe",
  stderr: "pipe",
});

const [stdout, stderr, exitCode] = await Promise.all([
  new Response(process.stdout).text(),
  new Response(process.stderr).text(),
  process.exited,
]);

if (exitCode !== 0) {
  throw new Error(`git status failed (${exitCode}): ${stderr}`);
}

Do not pass dynamic values through sh -c. Use Bun.spawn() argv or Bun Shell interpolation. Bun Shell escapes interpolated strings, but callers must still prevent option injection when user-controlled values can begin with -.

Modules and compatibility

Prefer ESM for new Bun code, but do not claim CommonJS is unsupported. Bun supports both. Follow the repository's import-extension convention; Bun does not require .ts extensions universally.

Use Buffer when an API contract requires it. It is a supported Uint8Array subclass. Prefer Uint8Array, ArrayBuffer, Blob, and Web streams for portable new interfaces.

Check Bun's Node compatibility table before replacing or adopting a Node API. Compatibility is API-specific, not all-or-nothing.

Servers and network clients

Use Bun.serve() for Bun-native HTTP or WebSocket servers and Web fetch() for outbound HTTP. Validate request data before use and make error paths explicit.

typescript
const server = Bun.serve({
  port: environment.PORT,
  routes: {
    "/health": new Response("ok"),
  },
  fetch(request) {
    return new Response(`Not found: ${new URL(request.url).pathname}`, { status: 404 });
  },
});

console.log(`Listening on ${server.url}`);

HTTP/2 and HTTP/3 support added in Bun 1.3.14 is experimental. Do not make production compatibility claims without testing the deployed protocol, TLS, proxy, and client path.

Show full SKILL.md (316 more words)Show less

Data clients

Bun includes SQL, Redis, SQLite, and S3 clients. Their APIs are not interchangeable:

  • Create a SQL connection with new SQL(connectionString) and execute parameterized queries with the connection's tagged template.
  • Use redis for the default client or new RedisClient(url) for an explicit connection; close explicit clients with .close().
  • Use bun:sqlite for embedded SQLite and Bun.s3 / S3Client for S3-compatible object storage.
  • Parse database and cache values at the boundary; generated TypeScript types are not runtime validation.

See references/data-networking.md for current examples and lifecycle details.

Security rules

  • Use Bun.password only for password hashing and verification. Its supported password algorithms are Argon2 and bcrypt; do not document scrypt as supported by this API.
  • Use Web Crypto or node:crypto for cryptographic digests and signatures. Bun.hash is non-cryptographic.
  • Bind CSRF tokens to a session identifier and verify them at mutation boundaries.
  • Treat the secrets API and newly introduced protocol support according to their documented stability level.
  • Never log secrets, full environment objects, authorization headers, or raw database URLs.

Tests and scheduled work

Use the repository's existing test command. Current Bun test capabilities include process isolation, parallel execution, sharding, and changed-file selection; choose flags deliberately so tests remain deterministic. Do not mask missing build artifacts with skipped tests.

Cron expressions schedule callbacks inside a running Bun process. OS cron support creates operating-system schedules. Neither is a durable distributed scheduler; use the system's established orchestration for retryable, observable production workflows.

Review checklist

  • Verify the project's pinned Bun version before using a recent API.
  • Keep CWD-relative and module-relative paths distinct.
  • Check every subprocess exit code and preserve stderr in failures.
  • Validate environment, HTTP, file, cache, and database input.
  • Use password and cryptographic hash APIs for their intended purposes.
  • Close explicit SQL, Redis, file, worker, and server resources when their lifecycle ends.
  • Mark experimental APIs and performance figures as conditional, not universal promises.
  • Prefer focused Bun-native APIs without banning supported Web or Node APIs.

© shepherdjerred, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in packages/dotfiles/dot_agents/skills/bun-runtime-best-practices of shepherdjerred/monorepo.

  • SKILL.md
  • references/data-networking.md
  • references/io-process-modules.md
  • references/release-notes-1.3.md

Open the folder on GitHubat commit da14ae9

Compare with similar skills

Bun Runtime Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bun Runtime Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bun Runtime Best Practices this skillshepherdjerred/monorepo112—~2kAutomated safety check: PassGPL-3.0
OpenTUI Terminal Interfacescline/cline70k—~1.9kAutomated safety check: PassApache-2.0
Monorepo Tooling and Dependenciespierrecomputer/pierre6.2k—~1.1kAutomated safety check: PassApache-2.0
Dead Code Removercode-yeongyu/oh-my-openagent70k1 repos~1.8kAutomated safety check: PassCustom licence
Bun Runtime and Toolkitmweinbach/agent-coworker156—~2.2kAutomated safety check: NotesCustom licence
holaOS App Builder SDKholaboss-ai/holaOS11k—~11kAutomated safety check: PassCustom licence

Similar skills

  • Helps build terminal user interfaces with OpenTUI using its core imperative API or its React and Solid reconcilers, with references for layout, keyboard, animation and testing.

    70k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Dead Code Remover

    code-yeongyu/oh-my-openagent

    Finds unused code in a TypeScript project, confirms each candidate has no references through the language server, then hands removals to parallel agents.

    70k GitHub starsUsed in 1 repo~1.8k tokens
    DevelopmentAuto-check passed
  • Bun Runtime and Toolkit

    mweinbach/agent-coworker

    Quick reference for using Bun to run TypeScript and JavaScript, install packages, bundle code, run tests and serve HTTP, with the key files and commands.

    156 GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • holaOS App Builder SDK

    holaboss-ai/holaOS

    Builds new holaOS apps with @holaboss/app-builder-sdk, either as integration-only MCP modules or as dashboard apps with a shadcn UI under src/client/.

    11k GitHub stars~11k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Bun

    galfrevn/apollo

    A skill your agent uses when building, running, testing, or bundling JavaScript/TypeScript applications.

    237 GitHub stars~2k tokensUpdated 1 mo ago
    Testing & QAAuto-check: notes

More from shepherdjerred/monorepo

All 63 skills in this repo
  • Bun Test Patterns

    shepherdjerred/monorepo

    Current Bun test runner guidance for discovery, isolation, parallelism, sharding, changed tests, mocks, timers, snapshots, coverage, DOM Testing Library, and integration teardown.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Bun Workspaces

    shepherdjerred/monorepo

    Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and…

    112 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Deep Research

    shepherdjerred/monorepo

    This skill should be used when the user asks to "deep research", "research this topic", "investigate thoroughly", "do a deep dive on", "comprehensive research on", "find everything about", "survey…

    112 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Figma Use

    shepherdjerred/monorepo

    This skill should be used when the user asks to "create a Figma design", "design in Figma", "make a Figma mockup", "create an app icon", "design UI", "render JSX to Figma", "export from Figma"…

    112 GitHub stars~946 tokensUpdated today
    Auto-check passed
  • Fish Helper

    shepherdjerred/monorepo

    Current Fish shell scripting, functions, abbreviations, completions, variables, events, configuration, plugins, testing, and safety guidance.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Gh Helper

    shepherdjerred/monorepo

    Complete GitHub operations via gh CLI - repos, issues, PRs, code search, releases, file management When user mentions GitHub, repositories, issues, PRs, gh command, code search, commits, file contents

    112 GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Bun Runtime Best Practices

What does Bun Runtime Best Practices do?

Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment. Bun Runtime Best Practices is an agent skill from shepherdjerred/monorepo. Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment.

When should I use Bun Runtime Best Practices?

Bun Runtime Best Practices fits situations like: reviewing Bun-only TypeScript; selecting Bun versus Web; migrating Node code to Bun.

How do I install Bun Runtime Best Practices in Claude Code?

Run `npx skills add shepherdjerred/monorepo --skill bun-runtime-best-practices -a claude-code`. Or copy the skill folder (packages/dotfiles/dot_agents/skills/bun-runtime-best-practices in shepherdjerred/monorepo) into .claude/skills/bun-runtime-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Bun Runtime Best Practices in Codex?

Run `npx skills add shepherdjerred/monorepo --skill bun-runtime-best-practices -a codex`. Or copy the skill folder (packages/dotfiles/dot_agents/skills/bun-runtime-best-practices in shepherdjerred/monorepo) into .agents/skills/bun-runtime-best-practices in your project. Codex loads it when a task matches its description.

Can I use Bun Runtime Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shepherdjerred/monorepo --skill bun-runtime-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bun-runtime-best-practices, .gemini/skills/bun-runtime-best-practices, .github/skills/bun-runtime-best-practices and .opencode/skills/bun-runtime-best-practices in your project.

What does Bun Runtime Best Practices need to run?

Going by SKILL.md and its folder, Bun Runtime Best Practices needs the command-line tools its instructions call (bun and sh).

Does Bun Runtime Best Practices access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bun Runtime Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bun Runtime Best Practices use?

Bun Runtime Best Practices is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bun Runtime Best Practices use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Bun Runtime Best Practices?

Skills that share tags, products or a category with Bun Runtime Best Practices: OpenTUI Terminal Interfaces (cline/cline, 70k stars), Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.2k stars), Dead Code Remover (code-yeongyu/oh-my-openagent, 70k stars) and Bun Runtime and Toolkit (mweinbach/agent-coworker, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bun Runtime Best Practices?

shepherdjerred (a GitHub user) maintains it in shepherdjerred/monorepo, which has 112 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 8, 2026.

Source: shepherdjerred/monorepo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.