bun-runtime
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the use of Bun's package manager to download and install dependencies from the npm registry.
- [COMMAND_EXECUTION]: Provides instructions for running scripts and executing package binaries using bun run and bunx.
- [INDIRECT_PROMPT_INJECTION]: The documentation covers building web servers that process external request data, which constitutes a potential attack surface. Ingestion points: HTTP route handlers and request parameters defined in Bun.serve (references/runtime-apis.md). Boundary markers: None explicitly defined in the instructional templates. Capability inventory: Includes file system writes (Bun.write), network operations (fetch), and database execution (bun:sqlite). Sanitization: Code examples correctly demonstrate the use of prepared statements for SQL operations to mitigate injection risks.
- [DYNAMIC_EXECUTION]: Describes the Bun.build API for bundling and compiling JavaScript/TypeScript code, as well as the execution of remote binaries via bunx.
Audit Metadata