secrets-detection

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is entirely focused on improving security posture by detecting and mitigating leaked credentials. It uses legitimate industry tools and follows established best practices.
  • [COMMAND_EXECUTION]: Provides standard command-line instructions for installing and running security tools like Gitleaks, TruffleHog, and Husky.
  • [EXTERNAL_DOWNLOADS]: References official and well-known repositories for security tools and pre-commit hooks, including GitHub repositories from Amazon Web Services (awslabs), Yelp, and the Gitleaks project.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Example secret patterns (AWS, GitHub, Stripe) and environment file templates use safe placeholders and are included solely for educational and detection purposes.
  • [CREDENTIALS_SAFE]: Actively encourages the use of secure storage solutions such as environment variables, .gitignore exclusion, and dedicated secret management services like AWS Secrets Manager and HashiCorp Vault.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 12:25 AM
Security Audit — agent-trust-hub — secrets-detection