secrets-management
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates security auditing by providing configuration for the trufflesecurity/trufflehog Docker image.- [EXTERNAL_DOWNLOADS]: Incorporates official GitHub Actions from trusted providers, including hashicorp/vault-action and aws-actions/configure-aws-credentials, for secure credential retrieval.- [COMMAND_EXECUTION]: Provides Bash and YAML templates that execute standard commands for vault, aws-cli, and docker to demonstrate secret retrieval and scanning workflows.- [DATA_EXFILTRATION]: Uses illustrative placeholder strings, such as 'password=secret', in documentation snippets to demonstrate configuration syntax safely.- [SAFE]: Explicitly promotes security hygiene by instructing the use of secret masking (::add-mask::) and advising against committing credentials to version control.
Audit Metadata