Skip to content
Ali Akbari
Menu

Security

Containment of a prompt-injected agent

Tested in CIenvironment:LabPersonal labboundedcode-prompt-injection-containment· cited on the résumé

Claim

An agent that follows injected instructions cannot weaken verification — a rewritten verification config is ignored because configuration is read from the base commit and the path is protected — and a host secret behind a planted symlink never reaches a context pack.

Status

tested
An automated test in CI asserts the claimed behaviour, including a failure case where relevant, and passes at the verified commit.
lab
Local machine, local clusters or CI runners.
personal lab
My own public repositories.

Verified commit

repository
akynte/boundedcode
release
v0.1.0-alpha.3
commit
be1aa9f87ec5ea92567d29c48bf1982ce018c227
committed
8 October 2026
CI
ci.yml #37773301609 success at be1aa9f

Curated source: paths, test names and the CI conclusion were checked against this commit by the evidence sync.

Implementation

Evidence

Environment

ci runner
GitHub-hosted ubuntu
go
1.27.1

Limitations

  • Tests encode specific attack scenarios; they do not prove resistance to every prompt-injection technique.
  • The agent in these tests is scripted to behave adversarially; no model is involved.
  • External penetration test or security audit: NOT VERIFIED.

Appears in

Related claims

Tested in CIenvironment:Lab

Hardened container arguments for agent execution

The container runner always builds engine arguments with no network, all capabilities dropped, no-new-privileges, a non-root user, read-only mounts where requested and tmpfs masks over secret paths, and refuses sensitive host mounts such as the home directory, ~/.ssh and the Docker socket.

Securityboundedcode v0.1.0-alpha.31 test file, 5 artifactsEvidence
Tested in CIenvironment:Lab

Fail-closed secret handling

The full verification gate errors when no secret scanner is available instead of passing silently, secret-looking paths (.env files, keys, Terraform state) are classified as secrets while ordinary source files are not, and API keys are redacted from escalation packets.

Securityboundedcode v0.1.0-alpha.33 test files, 7 artifactsEvidence