Tested in CI·environment:LabPersonal labboundedcode-prompt-injection-containment· cited on the résumé
Claim
An agent that follows injected instructions cannot weaken verification — a rewritten verification config is ignored because configuration is read from the base commit and the path is protected — and a host secret behind a planted symlink never reaches a context pack.
Status
tested
An automated test in CI asserts the claimed behaviour, including a failure case where relevant, and passes at the verified commit.
The container runner always builds engine arguments with no network, all capabilities dropped, no-new-privileges, a non-root user, read-only mounts where requested and tmpfs masks over secret paths, and refuses sensitive host mounts such as the home directory, ~/.ssh and the Docker socket.
Security·boundedcode v0.1.0-alpha.3·1 test file, 5 artifactsEvidence →
The full verification gate errors when no secret scanner is available instead of passing silently, secret-looking paths (.env files, keys, Terraform state) are classified as secrets while ordinary source files are not, and API keys are redacted from escalation packets.
Security·boundedcode v0.1.0-alpha.3·3 test files, 7 artifactsEvidence →