skills/cloudposse/atmos/atmos-ai/Gen Agent Trust Hub

atmos-ai

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of atmos ai skill install github.com/user/repo, which encourages users or agents to download and install extension content from unverified third-party GitHub repositories.
  • [COMMAND_EXECUTION]: The skill relies on several execution wrappers, such as atmos ai exec and atmos auth exec, which execute shell commands. It also configures MCP servers that run arbitrary subprocesses (e.g., atmos mcp start, uvx).
  • [INDIRECT_PROMPT_INJECTION]: The skill enables an environment where external AI assistants ingest Atmos stack configurations and component definitions to provide domain-specific knowledge, creating a vulnerability surface.
  • Ingestion points: The skill reads Atmos stack YAML files, component definitions, and repository structure to provide context to the agent.
  • Boundary markers: No specific boundary markers or 'ignore' instructions for processed data are specified in the provided instructions.
  • Capability inventory: The skill provides access to command execution via atmos ai exec, system tools through the Atmos MCP server, and credential-wrapped execution via atmos auth exec.
  • Sanitization: The instructions do not detail sanitization or escaping mechanisms for the repository content before it is interpolated into AI prompts.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and running MCP servers from the official AWS Labs repository (awslabs) using the uvx package runner. The documentation includes best-practice advice to pin these packages to specific versions rather than using the @latest tag to mitigate supply-chain risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:18 AM
Security Audit — agent-trust-hub — atmos-ai