Security audit
Pass Secrets
Security checks for vulnerabilities and agentic risk
Overview
This skill is a password-store helper, but it is too environment-specific for public install because it hardcodes a GPG recipient and operates on the user's local secret store.
Review this before installing. Only use it if you intentionally want the agent to interact with your local pass store, and do not store secrets using the hardcoded GPG recipient unless you have verified that the private key is under your control. Be aware that retrieval and env export commands can print secrets into the agent session or shell history/logs.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
