security-secrets-config-review

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and promotes security best practices such as secret rotation, least privilege, and audit logging. It does not incorporate any remote code execution, exfiltration patterns, or dangerous tool usage.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to analyze potentially untrusted pull request data and code changes.
  • Ingestion points: The skill instructs the agent to inspect "changed behavior and data flow" from external inputs (SKILL.md).
  • Boundary markers: No specific delimiters or boundary instructions are provided to distinguish between reviewer instructions and the data being reviewed.
  • Capability inventory: The skill defines a manual review process; it does not authorize the use of subprocesses, network tools, or file-writing capabilities.
  • Sanitization: No sanitization or escaping mechanisms are described for the data being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — security-secrets-config-review