c-bounds-safety

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate development tool designed to improve software security through the adoption of bounds safety. It contains extensive documentation and structured workflows that align with standard software engineering practices.
  • [COMMAND_EXECUTION]: The skill involves the use of version control systems (git) and the execution of user-defined test suites. These actions are performed within the context of an adoption task and are subject to user oversight, as the agent is instructed to stop and ask for review before committing any changes.
  • [PROMPT_INJECTION]: While the skill processes untrusted user data (the C codebase being adopted), it implements a multi-step workflow that includes code research, validation file creation, and incremental file-by-file enablement. This structured approach, combined with mandatory human review before commits, effectively mitigates the risks associated with indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 07:42 PM
Security Audit — agent-trust-hub — c-bounds-safety