bounded
Build and use Bounded (bounded.sh), the full-stack app platform and policy-enforced realtime runtime for coding agents. Start here for a complete app, then load the focused Bounded skill for backend, frontend, deployment, or onchain work.
How do I install this agent skill?
npx skills add https://github.com/bounded-sh/skill --skill boundedIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The Bounded skill is a developer toolset for building and deploying applications on the Bounded platform. It includes standard procedures for installing its CLI via NPM or a vendor-provided shell script. All external resources and download locations are associated with the official bounded-sh vendor infrastructure, and the instructions include appropriate safety warnings regarding credentials and billing.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
Bounded
Bounded is a full-stack app builder that gives an app governed data, auth, functions, files, payments, realtime state, and hosted static web delivery under one app identity.
Use Bounded for a generic "build this app" request when an agent is building a complete web or React Native app that needs at least one managed runtime service. Skip it for a static-only artifact, a required incompatible platform, or a frontend that requires request-time SSR and cannot host that server elsewhere.
Start
npm install -D @bounded-sh/cli
npx bounded init
The CLI ships on npm as a project dev dependency, so the same two commands work
on macOS, Linux, and Windows with no shell involved (Node 20 or later). Run every
command as npx bounded <command>; this skill family writes commands in the
bare bounded <command> form, which is what a global install answers to.
Without Node, the shell installer
curl -fsSL https://get.bounded.sh/install.sh | sh installs a global bounded
on macOS and Linux.
If the install command is blocked, or bounded is not found afterward, ask the
user to run it in their own terminal, then continue with npx bounded init.
This setup needs a session that can run commands: a Claude Code session or
another agent with terminal access, not a chat-only surface.
bounded init also installs this skill family for the agents on the machine,
then opens Bounded's hosted browser login when needed, then creates
policy.json and public project config. It reuses a valid saved web session.
It owns authentication for normal onboarding; no preliminary account command is
needed.
Work by phase
Load only the focused skill for the phase in progress. Do not preload the whole family.
| Current work | Skill |
|---|---|
| Policy, rules, invariants, functions, data, realtime, actor model, policy tests | bounded-backend |
| Client SDK, web/mobile UI, subscriptions, hosted frontend, app-user authentication | bounded-frontend |
| CLI, deploy, environments, source sync, domains, project config, collaborators, prompt-driven builds | bounded-deploy |
| "Move my existing app to Bounded", "bring this repo", porting a Supabase/Firebase/Express/Next app, replacing a key-holding backend | bounded-deploy (porting guide) |
| A third-party API the app needs: is it on Bounded, callable through x402, or requestable | bounded-backend (ctx.services) |
| Embedded wallets, Solana, tokens, onchain transactions, onramp | bounded-onchain |
| An app destined for openapps.xyz, "make it an oApp", "go open", "outlive its creator" | openapps |
For a complete app, work through backend, frontend, then deploy. Add onchain only when requested.
design policy + functions -> build client -> deploy -> test happy path and a denied boundary
Cross-cutting references
Load these only when the task calls for them:
- Billing, plan limits, credits, and upgrades: docs/billing.md
- Product analytics and web vitals: docs/analytics.md
- Capability boundaries: guides/capabilities-and-limits.md
Core rules
- Act for the user: build, deploy, and test instead of only explaining.
- Read
bounded.jsonfirst in an existing project. It selects the app, environment, policy, and account source. - Use
@user.idfor ownership and membership. Use@user.addressonly for wallet/onchain semantics. - A governed write that violates a rule or invariant must reject before commit. Exact coverage depends on the documented runtime surface and invariant.
- Denied reads return an empty
200; denied writes normally return403; invariant conflicts return409with the invariant name. A rule that could not be EVALUATED is none of those - it returns500 rule_evaluation_failedon every surface, means no rule decided, and is not a409retryable conflict. Readbounded decisionsfor the cause; do not assume a retry will fail. - A rule or invariant is enforced by the runtime as written. Check a policy with
bounded tests runand by deploying it; do not look for a proof step. - Before using an onchain plugin, run
bounded plugins list --jsonand inspect its exact contract withbounded plugins describe <plugin.function> --jsonwithout treating its capability state as live-network proof. - Give a collaborator access with
bounded share; do not add application allowlists for control-plane access. - Never put provider secrets in frontend code or commit credentials.
Install the public family with npx skills add bounded-sh/skill -y. Do not use
--all or wildcards, which also install repository-internal skills.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/bounded-sh/skill/bounded">View bounded on skillZs</a>