security-secrets-management
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes the use of reputable, industry-standard security tools for secret detection, including GitLeaks, TruffleHog, and GitGuardian (ggshield).
- [SAFE]: Architectural recommendations focus on secure, centralized storage solutions such as HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, and Azure Key Vault, emphasizing the avoidance of hardcoded secrets or plaintext environment variables.
- [SAFE]: The provided implementation patterns, such as the Python code for Vault authentication and CI/CD workflow examples, adhere to security best practices by utilizing workload identities (OIDC/Kubernetes Service Accounts) instead of long-lived static credentials.
- [SAFE]: The lifecycle management and incident response documentation provide sound operational guidance for handling credential leaks and maintaining security hygiene, aligning with major compliance standards like SOC 2 and PCI DSS.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration attempts were identified within the skill's instructions or reference materials.
Audit Metadata