secrets-management

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates security auditing by providing configuration for the trufflesecurity/trufflehog Docker image.- [EXTERNAL_DOWNLOADS]: Incorporates official GitHub Actions from trusted providers, including hashicorp/vault-action and aws-actions/configure-aws-credentials, for secure credential retrieval.- [COMMAND_EXECUTION]: Provides Bash and YAML templates that execute standard commands for vault, aws-cli, and docker to demonstrate secret retrieval and scanning workflows.- [DATA_EXFILTRATION]: Uses illustrative placeholder strings, such as 'password=secret', in documentation snippets to demonstrate configuration syntax safely.- [SAFE]: Explicitly promotes security hygiene by instructing the use of secret masking (::add-mask::) and advising against committing credentials to version control.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:35 PM
Security Audit — agent-trust-hub — secrets-management