So you trust Pedersen commitments and range proofs to prove that the inputs to a Confidential Transaction equals its outputs?
Is there scope for new implementation errors? Yes, but only in the fully generic sense of it involving _some_ new code. Anything that is different involves changes, and any change brings the possibility of an implementation error. However Blockstream has tried to keep confidential transactions as close to the underlying bitcoin code base as possible to minimize that error, and unlike other solutions CT has been subject to academic review and external security audit.
[Edit: updated paper link to the most recent version, which still doesn't have any proofs.]