secrets

Fail

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions to force the agent into an 'AUTONOMOUS MODE' with explicit commands to 'Do NOT ask questions' and 'Do NOT pause for confirmation'. This is a direct attempt to bypass the platform's safety guidelines and remove human-in-the-loop oversight for high-risk operations.
  • [COMMAND_EXECUTION]: The skill performs automated remediation (Phase 6) and file modifications (Phase 2, 3, 5) without requesting permission, which, combined with the autonomous mode instruction, allows for uncontrolled changes to the codebase and infrastructure.
  • [DATA_EXFILTRATION]: While the skill claims to audit for secrets, it performs broad scans for sensitive data including private keys (~/.ssh), AWS credentials, and .env files. In Phase 7 (Self-Evolution Telemetry), it writes execution metadata to a hidden path in the user's home directory (~/.claude/projects/skill-telemetry.md), which functions as a persistence and tracking mechanism outside the project's scope.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — secrets