secrets-scan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a security scanner intended for auditing and secret detection. It leverages industry-standard tools and provides structured steps for manual and automated analysis.
  • [DATA_EXPOSURE]: The instructions involve searching for sensitive files and patterns (e.g., .env files, AWS keys). This behavior is required for the skill's stated purpose. The skill explicitly directs the agent to redact any discovered secret values in its report to prevent exposure.
  • [INDIRECT_PROMPT_INJECTION]: As the skill processes external source code and configuration files, it is subject to potential indirect prompt injection. However, the risk is limited because the skill performs pattern matching and runs external scanners rather than executing the content of the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:29 PM
Security Audit — agent-trust-hub — secrets-scan