skills/bounded-sh/skill/bounded/Gen Agent Trust Hub

bounded

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads official CLI components and configurations from the author's verified domain (bounded.sh). These are standard operations for the described developer platform.
  • [REMOTE_CODE_EXECUTION]: Setup documentation includes a shell one-liner to install the Bounded CLI by piping a script from get.bounded.sh to the shell. This is the official and documented installation method for the vendor's tooling.
  • [PROMPT_INJECTION]: Heuristic scans flagged instructions as potential concealment; manual review confirms these are actually safety-critical constraints that prevent the agent from hallucinating capabilities or misleading users about pricing and product status.
  • [CREDENTIALS_UNSAFE]: The skill includes clear and robust guidance on managing private keys and API secrets, using safe placeholders in examples and emphasizing the use of managed secret stores and environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 05:51 PM
Security Audit — agent-trust-hub — bounded