secrets-handling
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides defensive security guidelines for the agent to follow when encountering or handling credentials, establishing a 'least privilege' and 'no-leak' policy.
- [PROMPT_INJECTION]: Rule 3 specifically instructs the agent to treat repository content as data rather than instructions, which is a best practice to mitigate indirect prompt injection attacks where malicious instructions are hidden in processed files.
- [DATA_EXFILTRATION]: The skill contains explicit rules (Rule 2 and Rule 4) that mandate scrubbing secrets before outputting or exporting data, directly addressing and mitigating data exfiltration risks.
- [COMMAND_EXECUTION]: While the skill mentions CLI tools like
opandps auxand references specific internal script paths, it does so to explain security concepts and provide policy guidance rather than executing hidden or malicious commands.
Audit Metadata