security-leak-guardrails

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: scripts/block-forbidden-staged-files.mjs uses execSync to run git diff --cached. scripts/secleak-check.sh executes gitleaks and trivy.
  • [EXTERNAL_DOWNLOADS]: Recommends installation of gitleaks, trivy, and node. References trusted GitHub Actions such as trufflesecurity/trufflehog and gitleaks/gitleaks-action.
  • [SAFE]: The skill provides standard security configuration and auditing tools. No malicious behavior detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 10:24 PM