infisical
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides best-practice guidance for secrets management, specifically instructing the agent on how to replace insecure methods like sharing
.envfiles with a centralized, encrypted vault. - [EXTERNAL_DOWNLOADS]: The skill references official Infisical dependencies, including the CLI (
@infisical/cli), SDK (@infisical/sdk), and GitHub Action (Infisical/secrets-action). These are well-known, legitimate tools from a reputable security organization. - [COMMAND_EXECUTION]: The provided commands (e.g.,
infisical login,infisical init,infisical run) are standard CLI operations for the service. The usage ofinfisical run -- [command]is the documented method for secure environment variable injection during runtime.
Audit Metadata