env-secrets-manager
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The auditing utility (
scripts/env_auditor.py) is designed to search local files for sensitive patterns like API keys and private keys. The script operates entirely within the local environment, reading file contents and reporting findings to the console or a JSON file without any network exfiltration capabilities. - [REMOTE_CODE_EXECUTION]: No remote code execution patterns or unauthorized downloads were detected. The documentation references well-known security tools like gitleaks and official platforms (AWS, GitHub, HashiCorp Vault) for legitimate secret management practices.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted files from a scanned repository, it does not use the extracted content to perform high-risk actions such as writing to the filesystem or executing shell commands, effectively mitigating the risk of data-driven prompt injection.
- [COMMAND_EXECUTION]: The skill provides templates for pre-commit hooks and validation scripts. These scripts follow standard development and DevOps practices and do not exhibit signs of privilege escalation or hidden execution.
Audit Metadata