bun-runtime

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of Bun's package manager to download and install dependencies from the npm registry.
  • [COMMAND_EXECUTION]: Provides instructions for running scripts and executing package binaries using bun run and bunx.
  • [INDIRECT_PROMPT_INJECTION]: The documentation covers building web servers that process external request data, which constitutes a potential attack surface. Ingestion points: HTTP route handlers and request parameters defined in Bun.serve (references/runtime-apis.md). Boundary markers: None explicitly defined in the instructional templates. Capability inventory: Includes file system writes (Bun.write), network operations (fetch), and database execution (bun:sqlite). Sanitization: Code examples correctly demonstrate the use of prepared statements for SQL operations to mitigate injection risks.
  • [DYNAMIC_EXECUTION]: Describes the Bun.build API for bundling and compiling JavaScript/TypeScript code, as well as the execution of remote binaries via bunx.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — bun-runtime