skills/cloudposse/atmos/atmos-auth/Gen Agent Trust Hub

atmos-auth

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the atmos auth exec and atmos auth shell commands, which allow for the execution of arbitrary shell commands and interactive sessions with injected cloud credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external authentication material (OIDC tokens, SAML responses, and SSO device codes) that dictates the security context for subsequent agent actions.
  • Ingestion points: OIDC tokens from GitHub Actions, GCP Workload Identity Federation tokens, and SAML assertions from identity providers like Okta or Google Apps.
  • Boundary markers: No specific delimiters for prompt-level token handling are defined; validation and exchange are handled by the underlying atmos CLI utility.
  • Capability inventory: Authentication network requests, writing configuration files (kubeconfig, Docker config) to standard XDG paths, and arbitrary command execution via atmos auth exec.
  • Sanitization: The skill relies on standard industry-standard authentication protocols (OpenID Connect, SAML 2.0, AWS SSO) to validate and exchange tokens.
  • [SAFE]: The skill demonstrates safe secret management by instructing users to use the !env YAML tag for sensitive credentials and recommending OS-native secure storage (keyrings) for cached session data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:18 AM
Security Audit — agent-trust-hub — atmos-auth