secrets-management-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality, security-focused instructions for secret management, correctly identifying common pitfalls like hardcoded defaults and logging of sensitive values.
- [SAFE]: Cryptographic implementations in the reference materials follow industry standards, such as using AES-GCM (AEAD) for authenticated encryption and emphasizing the importance of nonces and encryption contexts (references/ENCRYPTION.md).
- [SAFE]: The tool configuration is appropriately restricted using a whitelist for specific security and infrastructure CLIs (e.g., vault, aws, sops, gitleaks) rather than providing generic shell access.
- [SAFE]: External references point to well-known and trusted security resources including NIST, OWASP, and official cloud provider documentation.
Audit Metadata