bun-runtime

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains only informational content and technical examples for Bun. No attempts to override agent behavior, bypass safety guidelines, or extract system prompts were detected.
  • [DATA_EXFILTRATION]: No sensitive file access or network exfiltration patterns were found. The skill mentions using .env files for environment variable management, which is a standard and safe practice for secret handling.
  • [COMMAND_EXECUTION]: The skill documentation includes examples of using bun install and bun run. These are the primary functions of the Bun toolkit and are used here for legitimate educational purposes within the scope of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill mentions deployment and runtime support for Vercel, which is a well-known and trusted cloud platform. No downloads from unknown or suspicious third-party sources were found.
  • [OBFUSCATION]: The content is written in clear, plain-text markdown and standard code snippets. There is no evidence of Base64 encoding, zero-width characters, homoglyphs, or other obfuscation techniques.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides static documentation and does not process external, untrusted data at runtime that could lead to indirect injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — bun-runtime