secrets-detection
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill is entirely focused on improving security posture by detecting and mitigating leaked credentials. It uses legitimate industry tools and follows established best practices.
- [COMMAND_EXECUTION]: Provides standard command-line instructions for installing and running security tools like Gitleaks, TruffleHog, and Husky.
- [EXTERNAL_DOWNLOADS]: References official and well-known repositories for security tools and pre-commit hooks, including GitHub repositories from Amazon Web Services (awslabs), Yelp, and the Gitleaks project.
- [DATA_EXPOSURE_AND_EXFILTRATION]: Example secret patterns (AWS, GitHub, Stripe) and environment file templates use safe placeholders and are included solely for educational and detection purposes.
- [CREDENTIALS_SAFE]: Actively encourages the use of secure storage solutions such as environment variables, .gitignore exclusion, and dedicated secret management services like AWS Secrets Manager and HashiCorp Vault.
Audit Metadata