bun-server-queue

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS] (MEDIUM): The skill documentation references the @dangao/bun-server package and links to its GitHub repository. This source is not part of the trusted list of organizations or repositories, which introduces a supply-chain risk as the safety and integrity of the external code cannot be verified.\n- [DATA_EXFILTRATION] (LOW): The code examples demonstrate the use of the fetch() API for job processing. While this is a standard use case for background tasks, it constitutes a network operation surface targeting non-whitelisted domains. Users should ensure that any dynamic URLs passed to this function are strictly validated to prevent SSRF or unauthorized data transmission.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 09:10 AM