secrets-config
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is educational, providing guidelines and checklists for secure secret management without including any executable code or suspicious instructions.
- [SAFE]: No instances of prompt injection, obfuscation, or data exfiltration were found. The use of sensitive keywords like 'password' or 'api_key' is strictly for instructional purposes (e.g., as examples for grep commands or template placeholders).
- [SAFE]: External tools and services mentioned (HashiCorp Vault, AWS Secrets Manager, git-secrets, trufflehog) are widely recognized industry standards for security and auditing.
- [SAFE]: The skill explicitly advises against security risks like hardcoding credentials or committing .env files to version control.
Audit Metadata