atmos-aws-security
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could potentially contain malicious instructions intended to manipulate the agent's output or the generated infrastructure code.
- Ingestion points: According to the 'Context You Receive' section in
SKILL.md, the skill ingestsFinding details(specifically titles and descriptions) andComponent sourcecode from external sources. - Boundary markers: The skill instructions do not specify any delimiters or safety markers to differentiate between the agent's instructions and the potentially untrusted data being analyzed.
- Capability inventory: The skill is designed to generate sensitive infrastructure artifacts, including Terraform HCL changes, stack configuration (YAML), and deployment commands (
atmos terraform apply). - Sanitization: There is no evidence of input validation or sanitization to prevent malicious content within a security finding from influencing the remediation logic.
Audit Metadata