secrets-scanner
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides best-practice instructions for secret management, including rotation, detection, and prevention. All technical commands are consistent with the stated purpose of security auditing.
- [SAFE]: The skill references and integrates well-known security tools (gitleaks, trufflehog, detect-secrets, git-filter-repo) and official documentation from trusted organizations such as GitHub, NIST, and OWASP.
- [SAFE]: No evidence of obfuscation, unauthorized data exfiltration, hardcoded credentials, or malicious prompt injection was found.
- [SAFE]: The skill presents an Indirect Prompt Injection surface as it is designed to ingest and analyze untrusted repository data.
- Ingestion points: Repository files and git history (SKILL.md).
- Boundary markers: Not explicitly defined in the instructions.
- Capability inventory: Executes shell-based security tools and modifies repository configurations (SKILL.md).
- Sanitization: Not explicitly defined.
- Context: This behavior is the primary intended function of the skill and aligns with security industry standards.
Audit Metadata