skills/immamdouhaboammar/antigravity-superpowers/agency-secrets-credential-hygiene-engineer/Gen Agent Trust Hub
agency-secrets-credential-hygiene-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes a mock database connection string (
postgres://app:sup3rs3cret@db.internal:5432/app) within a documentation block. This string is used explicitly as a 'BEFORE' example to illustrate insecure coding practices that the agent is intended to detect and remediate. It does not represent a live or functional credential. - [EXTERNAL_DOWNLOADS]: The skill provides configuration examples that reference external tools, specifically the Gitleaks repository (
github.com/gitleaks/gitleaks) and its official GitHub Action (gitleaks/gitleaks-action@v2). These are well-known security utilities relevant to the skill's purpose of preventing secret leaks. - [PROMPT_INJECTION]: The instructions contain strongly worded directives such as 'Critical Rules You Must Follow' and 'Never Expose a Secret Value'. These are used to establish a defensive security persona and reinforce safety constraints regarding the handling of sensitive data, rather than attempting to override the agent's underlying safety filters.
Audit Metadata