varg-ai
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and installs the Bun runtime from the official
https://bun.sh/installURL using a piped shell command in the setup script. - [COMMAND_EXECUTION]: Executes media rendering and project management commands locally via
bunx vargaiandnpx -y skills. - [DATA_EXFILTRATION]: Manages the
VARG_API_KEYby reading from environment variables or~/.varg/credentialsand submitting it to the vendor's official endpoints (api.varg.ai,render.varg.ai, andapp.varg.ai) for service authentication. - [REMOTE_CODE_EXECUTION]: Includes functionality to submit agent-generated TypeScript (TSX) code to the cloud rendering endpoint at
https://render.varg.ai/api/renderfor video composition.
Audit Metadata