atmos-ai
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the use of
atmos ai skill install github.com/user/repo, which encourages users or agents to download and install extension content from unverified third-party GitHub repositories. - [COMMAND_EXECUTION]: The skill relies on several execution wrappers, such as
atmos ai execandatmos auth exec, which execute shell commands. It also configures MCP servers that run arbitrary subprocesses (e.g.,atmos mcp start,uvx). - [INDIRECT_PROMPT_INJECTION]: The skill enables an environment where external AI assistants ingest Atmos stack configurations and component definitions to provide domain-specific knowledge, creating a vulnerability surface.
- Ingestion points: The skill reads Atmos stack YAML files, component definitions, and repository structure to provide context to the agent.
- Boundary markers: No specific boundary markers or 'ignore' instructions for processed data are specified in the provided instructions.
- Capability inventory: The skill provides access to command execution via
atmos ai exec, system tools through the Atmos MCP server, and credential-wrapped execution viaatmos auth exec. - Sanitization: The instructions do not detail sanitization or escaping mechanisms for the repository content before it is interpolated into AI prompts.
- [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and running MCP servers from the official AWS Labs repository (
awslabs) using theuvxpackage runner. The documentation includes best-practice advice to pin these packages to specific versions rather than using the@latesttag to mitigate supply-chain risks.
Audit Metadata