secrets-vault-manager
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes utilities that ingest and process external data sources, creating a potential surface for indirect injection attacks.
- Ingestion points:
scripts/audit_log_analyzer.pyreads external Vault audit log files viaPath.read_text, andscripts/rotation_planner.pyreads JSON inventory files. - Boundary markers: The skill does not implement explicit boundary markers or instructions for the agent to ignore embedded commands within the ingested log/inventory data.
- Capability inventory: The skill possesses file-writing capabilities via
scripts/vault_config_generator.pyand execution context for Python scripts. - Sanitization: Data parsed from logs (such as metadata or error messages) is interpolated into reports without extensive sanitization against control characters or prompt instructions.
- [DYNAMIC_EXECUTION]: The
scripts/vault_config_generator.pyscript dynamically generates shell scripts (setup_*.sh) and HCL policy files based on user-provided flags. - Artifact Generation: It constructs executable setup scripts for various Vault secrets engines (KV, PKI, AWS, etc.) and auth methods.
- Review Requirement: While these scripts are intended for manual review and application by a systems administrator, they represent the generation of executable content at runtime.
Audit Metadata