skills/aeondave/malskill/trufflehog/Gen Agent Trust Hub

trufflehog

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides detailed CLI usage for the trufflehog utility, including subcommands for scanning filesystems, git repositories, and cloud providers like AWS S3 and Google Cloud Storage.
  • [COMMAND_EXECUTION]: The skill documents the unsafe flag in custom detector YAML configuration which allows bypassing TLS verification for internal verification endpoints, potentially exposing verification requests to man-in-the-middle risks if used on public networks.
  • [EXTERNAL_DOWNLOADS]: Documents integration with GitHub Actions using the official trufflesecurity/trufflehog repository for automated CI/CD secret scanning.
  • [CREDENTIALS_UNSAFE]: References the use of environment variables like $GITHUB_TOKEN to authenticate scans against private organization resources, which is the standard expected usage for this security tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a tool that ingests data from external sources (repositories, filesystems, cloud storage) to identify secrets.
  • Ingestion points: Reads content from local/remote git repos, S3 buckets, Docker images, and local filesystems (SKILL.md, references/custom-detectors.md).
  • Boundary markers: None explicitly defined in the documentation for handling tool output.
  • Capability inventory: The tool performs network operations to verify credentials against third-party APIs.
  • Sanitization: None mentioned for the data being scanned; however, the tool identifies patterns and entropy rather than executing instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — trufflehog