trufflehog
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides detailed CLI usage for the
trufflehogutility, including subcommands for scanning filesystems, git repositories, and cloud providers like AWS S3 and Google Cloud Storage. - [COMMAND_EXECUTION]: The skill documents the
unsafeflag in custom detector YAML configuration which allows bypassing TLS verification for internal verification endpoints, potentially exposing verification requests to man-in-the-middle risks if used on public networks. - [EXTERNAL_DOWNLOADS]: Documents integration with GitHub Actions using the official
trufflesecurity/trufflehogrepository for automated CI/CD secret scanning. - [CREDENTIALS_UNSAFE]: References the use of environment variables like
$GITHUB_TOKENto authenticate scans against private organization resources, which is the standard expected usage for this security tool. - [INDIRECT_PROMPT_INJECTION]: The skill describes a tool that ingests data from external sources (repositories, filesystems, cloud storage) to identify secrets.
- Ingestion points: Reads content from local/remote git repos, S3 buckets, Docker images, and local filesystems (SKILL.md, references/custom-detectors.md).
- Boundary markers: None explicitly defined in the documentation for handling tool output.
- Capability inventory: The tool performs network operations to verify credentials against third-party APIs.
- Sanitization: None mentioned for the data being scanned; however, the tool identifies patterns and entropy rather than executing instructions.
Audit Metadata