Vaultamagic is a script generator. The website never connects to CyberArk, never sees a credential, and never receives any of your data. Here's exactly what that means.
A 4-page review of the web page and the generated script: trust model, the exact CyberArk API calls, secret handling, and residual risks.
Get-Credential — never through this page.Read-only. Only GET requests, plus CyberArk's own read-a-secret call. No writes.
Authenticates with your credentials and logs off when finished. The session token stays in the local PowerShell session.
Paginated GET calls to enumerate Safes, the permission matrix, and accounts you're authorized to see.
GET calls to the AAM application endpoints, cross-referenced against Safe membership for access mapping.
Only if you opt in. Sends your reason, is audited by CyberArk, and never happens silently.
accounts-with-secrets.csv in clear text. Treat it as sensitive: restrict it, and delete it when your migration is done.Generate it, review the PowerShell, and you'll see there's nothing up our sleeve.