bun-development

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to download the Bun runtime from its official website.
  • Evidence: curl -fsSL https://bun.sh/install | bash in SKILL.md.
  • Evidence: powershell -c "irm bun.sh/install.ps1 | iex" in SKILL.md.
  • [REMOTE_CODE_EXECUTION]: Provides commands to execute installation scripts directly from the official Bun domain (bun.sh), which is a standard procedure for this developer tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates APIs for reading files (Bun.file) and handling HTTP requests (Bun.serve), which define an attack surface if an agent were to process untrusted data using these tools.
  • Ingestion points: Bun.file() reads and Bun.serve() fetch handlers in SKILL.md examples.
  • Boundary markers: None present in these illustrative code snippets.
  • Capability inventory: File system writes (Bun.write), database operations (bun:sqlite), and network server management (Bun.serve).
  • Sanitization: Not explicitly shown in the basic code examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — bun-development