atmos-custom-commands
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the use of Go templates to interpolate user-provided positional arguments and flags directly into shell commands, creating a potential command injection surface.
- Ingestion points: Positional arguments defined in
arguments, named flags defined inflags, and trailing arguments in{{ .TrailingArgs }}. - Boundary markers: None identified. Instructions do not recommend the use of delimiters or escaping when interpolating these values.
- Capability inventory: The skill explicitly supports arbitrary shell execution via
type: shellandtype: execsteps inSKILL.mdandreferences/command-syntax.md. - Sanitization: No evidence of sanitization or validation logic is provided in the documentation or templates to prevent malicious input from breaking out of shell contexts.
- [REMOTE_CODE_EXECUTION]: The skill documentation describes a
dependencies.toolsfield that allows for the automatic installation of external tools (e.g.,checkov,aws-cli,terraform) at runtime. - Evidence:
SKILL.mdandreferences/command-syntax.mddemonstrate declaring tool dependencies with version ranges (e.g.,checkov: "latest",terraform: "^1.10.0") which are resolved and installed by the underlying Atmos toolchain before command execution. - [COMMAND_EXECUTION]: The primary purpose of the skill is to facilitate the definition and execution of custom CLI commands that wrap shell scripts and Atmos operations.
- Evidence: The
stepsfield in the command definition schema supportstype: shell,type: exec, andtype: atmos, all of which involve spawning subprocesses to run potentially sensitive operations within the user's project environment.
Audit Metadata