infisical

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides best-practice guidance for secrets management, specifically instructing the agent on how to replace insecure methods like sharing .env files with a centralized, encrypted vault.
  • [EXTERNAL_DOWNLOADS]: The skill references official Infisical dependencies, including the CLI (@infisical/cli), SDK (@infisical/sdk), and GitHub Action (Infisical/secrets-action). These are well-known, legitimate tools from a reputable security organization.
  • [COMMAND_EXECUTION]: The provided commands (e.g., infisical login, infisical init, infisical run) are standard CLI operations for the service. The usage of infisical run -- [command] is the documented method for secure environment variable injection during runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 09:38 AM
Security Audit — agent-trust-hub — infisical