managing-infisical
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill employs environment variables for authentication ($INFISICAL_API_KEY), which is the recommended secure approach for handling sensitive credentials in scripts.
- [SAFE]: All network operations are performed against official Infisical API endpoints, which is a well-known technology service for secrets management.
- [SAFE]: The skill includes explicit instructions and utilizes 'jq' to ensure that only secret names and metadata are displayed, effectively preventing the accidental exfiltration or exposure of actual secret values.
- [SAFE]: The risk of indirect prompt injection from API data is mitigated by the use of structured data extraction (jq) which limits the content processed by the agent to specific, expected fields. Ingestion point: API responses in SKILL.md; Boundary markers: absent; Capability inventory: curl; Sanitization: jq field extraction.
Audit Metadata