env-secrets-manager

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is a legitimate security tool designed to improve secret management and prevent credential leakage. No malicious behaviors were detected.- [COMMAND_EXECUTION]: Provides scripts for local security tasks such as git history scanning, environment drift detection, and credential rotation. These tasks utilize well-known services and tools like HashiCorp Vault, AWS CLI, and OpenSSL.- [PROMPT_INJECTION]: Instructions focus strictly on the stated DevOps purpose without any attempts to bypass or override AI safety constraints or extract system prompts.- [DATA_EXFILTRATION]: No exfiltration patterns detected. The skill actively mitigates data exposure by providing scanners for hardcoded secrets and pre-defined .gitignore rules for sensitive files like .ssh and .aws/credentials.- [SAFE]: Regarding indirect prompt injection: (1) Ingestion points: The sync checker, validator, and secret scanner scripts read local project files and environment variables. (2) Boundary markers: None. (3) Capability inventory: Markdown documents Bash scripts executing curl, vault, aws, and doppler. (4) Sanitization: Ingested data is processed using structural parsing (key=value) or regular expression matching.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 01:08 AM