bun
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a technical reference for Bun, a well-known and legitimate JavaScript runtime. All external links point to the official
bun.comdocumentation. - [INDIRECT_PROMPT_INJECTION]: The skill documents a runtime environment that ingests external data and possesses significant system capabilities.
- Ingestion points: Project configuration files (
package.json,bunfig.toml) and runtime inputs like HTTP requests handled byBun.serve()or files read viaBun.file(). - Boundary markers: None defined; the skill is a general command reference rather than a prompt template.
- Capability inventory: The tool allows for arbitrary command execution (
Bun.spawn()), file system modifications (Bun.write()), and network communications (fetch,Bun.serve()). - Sanitization: Not applicable to this documentation; standard security practices for runtime environments apply to the developer using the tool.
Audit Metadata