atmos-components
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill describes functionality for just-in-time provisioning of components from remote sources including Git, OCI, S3, and HTTP.
- Evidence:
source: "github.com/cloudposse-terraform-components/aws-vpc.git?ref=1.450.0"inSKILL.md. Note: The resource originates from the vendor's official GitHub repository. - [EXTERNAL_DOWNLOADS]: The
dependencies.toolsfeature allows Atmos to automatically install and inject runtime CLI tools at various configuration scopes. - Evidence: Description of
dependencies.toolsinSKILL.mdstates "Atmos auto-installs and injects them, so do not add a separate install step." - [COMMAND_EXECUTION]: Components can override the default executable command, which allows for the execution of arbitrary binaries in place of standard infrastructure tools.
- Evidence: The
commandfield in the component configuration table inSKILL.mdallows users to "Override the executable (e.g.,tofuinstead ofterraform)." - [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture where the agent processes potentially untrusted data from stack manifests and remote state outputs, which are then interpolated into execution contexts.
- Ingestion points:
SKILL.md,references/examples.md(Stack manifests,vars,env, and!terraform.statefunctions). - Boundary markers: None mentioned; the documentation does not describe explicit delimiters for untrusted variable values.
- Capability inventory:
SKILL.md(Subprocess execution ofterraform,helmfile, andpackerviaatmoscommands). - Sanitization: Not specified; the documentation does not mention validation or escaping of stack variables before execution.
- [DYNAMIC_EXECUTION]: The skill outlines several mechanisms for dynamic code and configuration generation.
- Evidence:
references/component-types.mddescribes Atmos generatingbackend.tf.jsonandproviders_override.tf.jsonfiles at runtime. - Evidence:
references/examples.mddemonstrates the use of Go Templates (eks-{{ .flavor }}/cluster) to dynamically generate component configurations based on context.
Audit Metadata