Tool Open source

Bashka

Bashka is a command-line safety guard for the `curl ... | bash` installation pattern. It parses incoming shell scripts, scores them against checks for credential theft, data exfiltration, reverse shells, destructive commands, insecure downloads, persistence, obfuscation, and other hazards, and can follow forwarded or nested scripts so each layer is reviewed before execution. It can also provide the script for manual or AI-assisted analysis.

View repository Mentioned in 1 video ↓

Overview

Bashka records software installed through it in an installation registry, including detected binaries and created directories. Its commands can list and inspect recorded packages, rerun their installers, and remove tracked files. It supports configuration for review behavior, remote-script following, recursion depth, command limits, trusted domains, and interface style.

The project is open source under the MIT license and is distributed as a shell-installed or prebuilt binary, including through Homebrew, Cargo, mise, and GitHub releases. Its documentation notes that static analysis cannot reliably detect every behavior in a Turing-complete shell script, that direct paths such as `/bin/bash` bypass its PATH shim, and that the registry cannot manage files whose installation locations it cannot detect.

What Bashka is used for

1 use taken from transcripts — each links to the moment in the video.

  • Inspects shell installers before execution, flagging credential theft, destructive commands, and unverified downloads. It can follow nested downloads and record installed binaries for later review or removal.

Videos mentioning Bashka

1 in the library.