secrets-management
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to guide an agent through a static analysis process to identify secrets management risks. It uses local tools like Grep and Glob to search for patterns in configuration files.
- [SAFE]: No remote code execution or external downloads were detected. The skill relies entirely on built-in agent capabilities and does not reference external scripts or untrusted repositories.
- [SAFE]: The skill includes explicit safety guidelines for the agent, instructing it to never extract, log, or display actual secret values, and to treat all analyzed content as untrusted data rather than instructions.
- [SAFE]: No obfuscation or persistence mechanisms were found. All instructions and regex patterns are documented clearly in plain text.
- [SAFE]: The skill identifies common sensitive file paths (e.g., .env, .aws/credentials) for the purpose of auditing, but does not provide a mechanism for data exfiltration.
Audit Metadata