vault
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill provides comprehensive guides and examples for setting up Vault, configuring secrets engines (KV, Database, PKI, Transit), and managing access policies. All instructions are consistent with established DevOps best practices for HashiCorp Vault.
- [NO_CODE]: No executable scripts (.sh, .py, .js) or binary assets are bundled with this skill. The logic is entirely declarative, consisting of markdown instructions and configuration templates, which significantly limits the potential for unauthorized code execution.
- [DATA_EXFILTRATION]: The skill includes standard configuration examples for Kubernetes authentication that reference system paths such as /var/run/secrets/kubernetes.io/serviceaccount/token. This is the expected and necessary method for integrating Vault with Kubernetes and does not represent an exfiltration attempt in this context.
Audit Metadata