sops-encrypt

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands (sops, python3, rm) in SKILL.md that incorporate file paths as arguments. This interpolation surface could be exploited if filenames contain shell metacharacters.\n- [DATA_EXFILTRATION]: By design, this skill accesses and processes unencrypted sensitive data in .env files (SKILL.md). While the goal is local encryption, any process with read access to secrets requires high trust.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the filesystem.\n
  • Ingestion points: Filenames and existence of .env files (SKILL.md).\n
  • Boundary markers: None specified in the shell command templates (SKILL.md).\n
  • Capability inventory: Shell command execution via python3, sops, and rm (SKILL.md).\n
  • Sanitization: No explicit sanitization or escaping of the file placeholder is mentioned (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 10:55 AM
Security Audit — agent-trust-hub — sops-encrypt