secrets

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent and proportionate footprint for managing TrueFoundry secret groups and secrets using Bash and a defined API shim. It emphasizes secret-masking, environment-variable usage for sensitive values, and HITL approvals for destructive operations, which aligns with the stated purpose. There are moderate security considerations around ensuring no leakage via logs or history and confirming that tfy-api.sh is trusted and kept up-to-date. No unverifiable binaries or external exfiltration patterns are evident from the provided description. Overall, the risk posture is acceptable (benign-to-suspicious) given proper operational controls, with recommended tightening around explicit logging behavior and explicit sourcing/verification of the tfy-api.sh script path.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/truefoundry%2Ftfy-agent-skills%2Fsecrets%2F@ac8b4b81c6af73c8908d0afe2f588d4cb6488ec6