Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The script accepts an arbitrary string argument and executes it with shell eval, which enables unrestricted command execution. This materially exceeds the stated purpose of providing Bun-specific runtime helpers and makes the skill capable of running any shell payload the caller can supply, including destructive filesystem, process, or network actions.
