secrets-env-manager
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS] (LOW): The provided GitHub Action workflow templates reference third-party actions using unpinned branch references.
- Evidence: 'trufflesecurity/trufflehog@main' and 'reviewdog/action-detect-secrets@master' in SKILL.md.
- Risk: Using unpinned versions allows upstream maintainers to change the code executed in the environment without notice, which could lead to supply chain attacks. It is recommended to pin actions to a specific commit SHA.
Audit Metadata