skills/cloudposse/atmos/atmos-ci/Gen Agent Trust Hub

atmos-ci

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and examples for configuring Atmos CI, focusing on native commands rather than deprecated wrapper actions. All instructions are consistent with the stated purpose of CI/CD automation.
  • [SAFE]: External resource references, such as the container image ghcr.io/cloudposse/atmos and tool providers hashicorp/terraform or opentofu/opentofu, are either vendor-owned or from well-known trusted services.
  • [SAFE]: The implementation of GitHub Actions secrets (GITHUB_TOKEN) and OIDC-based authentication (id-token: write) follows official security best practices for identity management in CI/CD environments.
  • [SAFE]: No obfuscation, data exfiltration, unauthorized persistence mechanisms, or prompt injection patterns were detected during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:49 AM
Security Audit — agent-trust-hub — atmos-ci