agency-secrets-credential-hygiene-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes a mock database connection string (postgres://app:sup3rs3cret@db.internal:5432/app) within a documentation block. This string is used explicitly as a 'BEFORE' example to illustrate insecure coding practices that the agent is intended to detect and remediate. It does not represent a live or functional credential.
  • [EXTERNAL_DOWNLOADS]: The skill provides configuration examples that reference external tools, specifically the Gitleaks repository (github.com/gitleaks/gitleaks) and its official GitHub Action (gitleaks/gitleaks-action@v2). These are well-known security utilities relevant to the skill's purpose of preventing secret leaks.
  • [PROMPT_INJECTION]: The instructions contain strongly worded directives such as 'Critical Rules You Must Follow' and 'Never Expose a Secret Value'. These are used to establish a defensive security persona and reinforce safety constraints regarding the handling of sensitive data, rather than attempting to override the agent's underlying safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 07:55 AM
Security Audit — agent-trust-hub — agency-secrets-credential-hygiene-engineer