secrets-manager

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment describes a coherent secrets-management tool aligned with its purpose, but introduces notable security and supply-chain concerns: Git-based installation (higher supply-chain risk), plaintext import/export paths (plaintext exposure risk), and environment-injection of secrets into subprocesses (potential leakage). Recommend tightening: pin dependencies/commits, document key management policies (rotation, revocation), restrict and audit MCP access, ensure authenticated and authorized communications, and minimize plaintext exposure by avoiding or securing export/import workflows and enforcing least-privilege access. Overall, treat as high-risk and in need of strong operational controls and provenance guarantees.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 03:10 AM
Package URL
pkg:socket/skills-sh/ylz201%2Fkeyvault%2Fsecrets-manager%2F@1e6820fbcb1ddf1d2269f5527117b35d04cf16a6