fnox-providers
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The documentation references sensitive system paths like
~/.ssh/id_ed25519and~/.aws/credentialsfor tool configuration. It also advises users to create unencrypted copies of password-protected SSH keys for usage with the age provider, which is a security best-practice violation. - [COMMAND_EXECUTION]: The skill provides instructions for users to modify their shell profiles (e.g.,
~/.zshrc) to persist decryption keys and other environment variables required for the tool's operation. - [EXTERNAL_DOWNLOADS]: Recommends installing various third-party CLI utilities (e.g.,
age,1password-cli,doppler) via standard system package managers such as brew or apt.
Audit Metadata