keeper-secrets

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the installation of the keeper-secrets-manager-cli package from PyPI and mentions downloading official binaries from the vendor's GitHub repository.
  • [COMMAND_EXECUTION]: The skill utilizes the ksm exec utility to execute arbitrary shell commands with secrets dynamically injected into the process environment. It also includes commands for programmatically adding, updating, and deleting records within the Keeper Vault.
  • [DATA_EXFILTRATION]: The skill describes the ksm sync feature, which facilitates the synchronization of sensitive vault records to external cloud services (AWS Secrets Manager, Azure Key Vault) or user-specified HTTP endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 01:38 AM