skills/cloudposse/atmos/atmos-ansible/Gen Agent Trust Hub

atmos-ansible

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to wrap and execute the ansible-playbook command. It facilitates passing native flags (including privilege escalation flags like --become) and environment variables to the subprocess. It also allows overriding the executable binary via configuration manifests.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests configuration from stack manifests and component files, which are used to generate variables and environment settings for command execution.
  • Ingestion points: Stack manifests (YAML) and Ansible component directories (containing playbooks, roles, and inventory) as specified in SKILL.md.
  • Boundary markers: No specific delimiters or boundary markers are mentioned to isolate untrusted configuration data.
  • Capability inventory: The skill possesses capabilities for file system writes (temporary variable files) and subprocess execution (ansible-playbook).
  • Sanitization: No specific sanitization or validation logic is described for the content of the manifests beyond standard YAML parsing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-ansible