Information
The secrets list stores passwords that are required for remote storage connections or other purposes. These passwords may be visible in clear-text to anyone able to log into the host.
http://blog.403labs.com/post/57428499719/revealing-xenserver-storage-repository-secrets
Solution
Use generic, least-privileged accounts that only have access to the storage repositories. Never mount storage repositories with a privileged Active Directory account.