atmos-aws-compliance
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents and enables the execution of the
atmos aws compliance reportcommand, which interacts with AWS Security Hub and local stack configurations. - [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection by processing external data from AWS Security Hub findings for use in reports and AI-generated summaries via the
--aiflag. * Ingestion points: Compliance findings retrieved from AWS Security Hub. * Boundary markers: None specified in the documentation or command model. * Capability inventory: File system writing (--file) and AI-based summary generation (--ai). * Sanitization: No explicit sanitization of external finding text is documented.
Audit Metadata