dotenvx-secrets

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill references an installation command that downloads and executes a script directly from https://dotenvx.sh using 'curl -sfS https://dotenvx.sh | sh'.
  • [EXTERNAL_DOWNLOADS]: Downloads the dotenvx utility and its associated dependencies from its official distribution point.
  • [PERSISTENCE_MECHANISMS]: Features instructions for installing a Git pre-commit hook using 'dotenvx precommit --install', which adds a script to '.git/hooks/pre-commit' to prevent committing unencrypted secrets.
  • [COMMAND_EXECUTION]: Employs the 'dotenvx run' command to execute child processes while injecting environment variables into their context.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from environment files and external vaults. * Ingestion points: Contents of .env files and secrets retrieved from 1Password or Bitwarden. * Boundary markers: Documents the limitations of the --redact flag and warns that it does not protect against transformed or encoded secrets. * Capability inventory: Access to shell execution, file system modifications (Git hooks), and decryption tools. * Sanitization: Uses execFile with argument arrays to prevent shell injection when resolving vault references.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — dotenvx-secrets