bun-server-queue
Warn
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS] (MEDIUM): The skill documentation references the
@dangao/bun-serverpackage and links to its GitHub repository. This source is not part of the trusted list of organizations or repositories, which introduces a supply-chain risk as the safety and integrity of the external code cannot be verified.\n- [DATA_EXFILTRATION] (LOW): The code examples demonstrate the use of thefetch()API for job processing. While this is a standard use case for background tasks, it constitutes a network operation surface targeting non-whitelisted domains. Users should ensure that any dynamic URLs passed to this function are strictly validated to prevent SSRF or unauthorized data transmission.
Audit Metadata