audit-secrets

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git log and grep to scan the repository history. This is a standard and expected method for identifying secrets that were committed and subsequently deleted.
  • [CREDENTIALS_UNSAFE]: While the skill contains regex patterns for credentials (e.g., AWS, Stripe, JWT), these are used for detection purposes. The instructions explicitly command the agent to mask all findings and never print full secret values, which follows security best practices.
  • [REMOTE_CODE_EXECUTION]: The remediation step recommends git filter-repo. This is a well-known, trusted utility for safely rewriting git history to remove sensitive data.
  • [DATA_EXFILTRATION]: There are no network operations or external data transmissions. The audit is performed locally on the user's working tree and git history.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — audit-secrets