dotenvx-secrets
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill references an installation command that downloads and executes a script directly from https://dotenvx.sh using 'curl -sfS https://dotenvx.sh | sh'.
- [EXTERNAL_DOWNLOADS]: Downloads the dotenvx utility and its associated dependencies from its official distribution point.
- [PERSISTENCE_MECHANISMS]: Features instructions for installing a Git pre-commit hook using 'dotenvx precommit --install', which adds a script to '.git/hooks/pre-commit' to prevent committing unencrypted secrets.
- [COMMAND_EXECUTION]: Employs the 'dotenvx run' command to execute child processes while injecting environment variables into their context.
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from environment files and external vaults. * Ingestion points: Contents of .env files and secrets retrieved from 1Password or Bitwarden. * Boundary markers: Documents the limitations of the --redact flag and warns that it does not protect against transformed or encoded secrets. * Capability inventory: Access to shell execution, file system modifications (Git hooks), and decryption tools. * Sanitization: Uses execFile with argument arrays to prevent shell injection when resolving vault references.
Audit Metadata