infisical-secret-scanning

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive guide for configuring and using Infisical Secret Scanning tools, including its CLI and cloud integrations. It provides instructional content for developers to detect and remediate leaked credentials.
  • [EXTERNAL_DOWNLOADS]: The documentation references the default configuration file hosted on the official Infisical GitHub repository (https://raw.githubusercontent.com/Infisical/infisical/main/cli/config/infisical-scan.toml). This reference to a well-known service and the vendor's own infrastructure is documented neutrally as a source for rules and entropy thresholds.
  • [COMMAND_EXECUTION]: The skill provides examples of standard CLI commands (e.g., infisical scan, infisical scan install --pre-commit-hook) intended for local use by a developer to detect secret leaks in git history or staged changes. These commands are consistent with the skill's stated purpose and follow established development practices for secret prevention.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:05 PM
Security Audit — agent-trust-hub — infisical-secret-scanning