vault-secrets-integrator
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE] (SAFE): The skill consists only of a SKILL.md file containing documentation and metadata. No scripts, binaries, or configuration files were provided for analysis.
- [COMMAND_EXECUTION] (SAFE): Although the skill metadata lists Bash as an allowed tool, no command-line logic or automated scripts are included in the skill content.
- [Indirect Prompt Injection] (SAFE): The skill processes DevOps configuration files which creates a potential attack surface. 1. Ingestion points: Implicitly reads DevOps configuration files via Grep and Read tools. 2. Boundary markers: None present in documentation. 3. Capability inventory: Bash, Write, Edit tools allowed. 4. Sanitization: None provided in the current skill definition.
Audit Metadata