skills/midudev/autoskills/bun/Gen Agent Trust Hub

bun

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical reference for Bun, a well-known and legitimate JavaScript runtime. All external links point to the official bun.com documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a runtime environment that ingests external data and possesses significant system capabilities.
  • Ingestion points: Project configuration files (package.json, bunfig.toml) and runtime inputs like HTTP requests handled by Bun.serve() or files read via Bun.file().
  • Boundary markers: None defined; the skill is a general command reference rather than a prompt template.
  • Capability inventory: The tool allows for arbitrary command execution (Bun.spawn()), file system modifications (Bun.write()), and network communications (fetch, Bun.serve()).
  • Sanitization: Not applicable to this documentation; standard security practices for runtime environments apply to the developer using the tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:00 PM
Security Audit — agent-trust-hub — bun