secrets-env-manager

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The provided GitHub Action workflow templates reference third-party actions using unpinned branch references.
  • Evidence: 'trufflesecurity/trufflehog@main' and 'reviewdog/action-detect-secrets@master' in SKILL.md.
  • Risk: Using unpinned versions allows upstream maintainers to change the code executed in the environment without notice, which could lead to supply chain attacks. It is recommended to pin actions to a specific commit SHA.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 08:48 PM