secrets-management
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive standards and templates for secrets management, following NIST 800-53r5 SC-12 compliance.
- [SAFE]: All environment variable examples use placeholders and include clear warnings against committing real credentials.
- [SAFE]: External tool references for secret scanning, including TruffleHog, Gitleaks, and detect-secrets, target well-known and reputable security projects.
- [SAFE]: The included rotation script (
rotate-secrets.sh) implements robust security practices, including dry-run functionality, backup procedures, and the use of official CLI tools for interaction with secrets managers.
Audit Metadata