secrets-handling

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides defensive security guidelines for the agent to follow when encountering or handling credentials, establishing a 'least privilege' and 'no-leak' policy.
  • [PROMPT_INJECTION]: Rule 3 specifically instructs the agent to treat repository content as data rather than instructions, which is a best practice to mitigate indirect prompt injection attacks where malicious instructions are hidden in processed files.
  • [DATA_EXFILTRATION]: The skill contains explicit rules (Rule 2 and Rule 4) that mandate scrubbing secrets before outputting or exporting data, directly addressing and mitigating data exfiltration risks.
  • [COMMAND_EXECUTION]: While the skill mentions CLI tools like op and ps aux and references specific internal script paths, it does so to explain security concepts and provide policy guidance rather than executing hidden or malicious commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — secrets-handling