atmos-auth
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the
atmos auth execandatmos auth shellcommands, which allow for the execution of arbitrary shell commands and interactive sessions with injected cloud credentials. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external authentication material (OIDC tokens, SAML responses, and SSO device codes) that dictates the security context for subsequent agent actions.
- Ingestion points: OIDC tokens from GitHub Actions, GCP Workload Identity Federation tokens, and SAML assertions from identity providers like Okta or Google Apps.
- Boundary markers: No specific delimiters for prompt-level token handling are defined; validation and exchange are handled by the underlying
atmosCLI utility. - Capability inventory: Authentication network requests, writing configuration files (kubeconfig, Docker config) to standard XDG paths, and arbitrary command execution via
atmos auth exec. - Sanitization: The skill relies on standard industry-standard authentication protocols (OpenID Connect, SAML 2.0, AWS SSO) to validate and exchange tokens.
- [SAFE]: The skill demonstrates safe secret management by instructing users to use the
!envYAML tag for sensitive credentials and recommending OS-native secure storage (keyrings) for cached session data.
Audit Metadata