skills/varghq/skills/varg-ai/Gen Agent Trust Hub

varg-ai

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the Bun runtime from the official https://bun.sh/install URL using a piped shell command in the setup script.
  • [COMMAND_EXECUTION]: Executes media rendering and project management commands locally via bunx vargai and npx -y skills.
  • [DATA_EXFILTRATION]: Manages the VARG_API_KEY by reading from environment variables or ~/.varg/credentials and submitting it to the vendor's official endpoints (api.varg.ai, render.varg.ai, and app.varg.ai) for service authentication.
  • [REMOTE_CODE_EXECUTION]: Includes functionality to submit agent-generated TypeScript (TSX) code to the cloud rendering endpoint at https://render.varg.ai/api/render for video composition.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 03:58 PM