secrets-management
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for static analysis and pattern matching. It uses restricted tools (
Read,Grep,Glob) to identify potential security gaps in a codebase. - [PROMPT_INJECTION]: The skill includes a 'Prompt Injection Safety Notice' that explicitly instructs the agent to treat file content as untrusted data and ignore any instructions found within analyzed files.
- [DATA_EXFILTRATION]: Instructions strictly prohibit the logging, extraction, or display of actual secret values, focusing only on detection patterns and configuration practices.
- [EXTERNAL_DOWNLOADS]: References external documentation and tools from established organizations (OWASP, NIST, GitHub, Yelp, HashiCorp). All links target official domains or reputable public repositories.
Audit Metadata