secrets-scanner

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides best-practice instructions for secret management, including rotation, detection, and prevention. All technical commands are consistent with the stated purpose of security auditing.
  • [SAFE]: The skill references and integrates well-known security tools (gitleaks, trufflehog, detect-secrets, git-filter-repo) and official documentation from trusted organizations such as GitHub, NIST, and OWASP.
  • [SAFE]: No evidence of obfuscation, unauthorized data exfiltration, hardcoded credentials, or malicious prompt injection was found.
  • [SAFE]: The skill presents an Indirect Prompt Injection surface as it is designed to ingest and analyze untrusted repository data.
  • Ingestion points: Repository files and git history (SKILL.md).
  • Boundary markers: Not explicitly defined in the instructions.
  • Capability inventory: Executes shell-based security tools and modifies repository configurations (SKILL.md).
  • Sanitization: Not explicitly defined.
  • Context: This behavior is the primary intended function of the skill and aligns with security industry standards.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:30 PM
Security Audit — agent-trust-hub — secrets-scanner