no-secret-leak-guard
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a protective guardrail, providing detection patterns and procedures to ensure that credentials are never hardcoded or committed to version control.
- [SAFE]: It explicitly addresses the 'Comment-and-Control' attack vector (indirect prompt injection) by teaching the agent to treat repository collaboration text (PR titles, issue descriptions, comments) as untrusted data rather than authoritative instructions.
- [SAFE]: The sensitive file paths and regex patterns provided in the reference files are used solely for the purpose of identification and redaction of secrets, conforming to security best practices.
- [SAFE]: No malicious patterns such as obfuscation, exfiltration, or remote code execution were detected in the skill instructions or configuration.
Audit Metadata