bounded-frontend
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains documentation for the
@bounded-sh/clientand@bounded-sh/serverSDKs. All described operations, including data fetching (get,search), atomic writes (setMany), and real-time subscriptions, are routed through a server-side policy enforcement engine. - [SAFE]: Legitimate security guidance is provided regarding a moderate transitive dependency vulnerability (GHSA-w5hq-g745-h8pq) in the
uuidpackage. The documentation correctly instructs developers to apply package manager overrides/resolutions to mitigate the risk. - [SAFE]: Authentication mechanisms detailed in the guides (OAuth2 with PKCE, Solana SIWS, and Turnkey-based embedded wallets) utilize secure, hosted issuers such as auth.bounded.sh. The React Native integration guide specifically advocates for best practices like encrypting session stores at rest using platform-specific hardware keychains.
- [SAFE]: External dependencies and integration examples are restricted to well-known technology ecosystems, including Solana mobile wallet standards, Expo, React Native, and Privy. These are documented as optional integrations to extend application functionality.
- [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were found. The skill's metadata and instructional content are consistent with its primary purpose as an SDK documentation resource.
Audit Metadata