A user can create secrets into any repository they've installed the app on. It should be possible to create secrets into an org, too, but this requires a different permission scope and a slightly different github API endpoint.