bun-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to download the Bun runtime from its official website.
- Evidence:
curl -fsSL https://bun.sh/install | bashinSKILL.md. - Evidence:
powershell -c "irm bun.sh/install.ps1 | iex"inSKILL.md. - [REMOTE_CODE_EXECUTION]: Provides commands to execute installation scripts directly from the official Bun domain (bun.sh), which is a standard procedure for this developer tool.
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates APIs for reading files (
Bun.file) and handling HTTP requests (Bun.serve), which define an attack surface if an agent were to process untrusted data using these tools. - Ingestion points:
Bun.file()reads andBun.serve()fetch handlers inSKILL.mdexamples. - Boundary markers: None present in these illustrative code snippets.
- Capability inventory: File system writes (
Bun.write), database operations (bun:sqlite), and network server management (Bun.serve). - Sanitization: Not explicitly shown in the basic code examples.
Audit Metadata