atmos-custom-commands

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the use of Go templates to interpolate user-provided positional arguments and flags directly into shell commands, creating a potential command injection surface.
  • Ingestion points: Positional arguments defined in arguments, named flags defined in flags, and trailing arguments in {{ .TrailingArgs }}.
  • Boundary markers: None identified. Instructions do not recommend the use of delimiters or escaping when interpolating these values.
  • Capability inventory: The skill explicitly supports arbitrary shell execution via type: shell and type: exec steps in SKILL.md and references/command-syntax.md.
  • Sanitization: No evidence of sanitization or validation logic is provided in the documentation or templates to prevent malicious input from breaking out of shell contexts.
  • [REMOTE_CODE_EXECUTION]: The skill documentation describes a dependencies.tools field that allows for the automatic installation of external tools (e.g., checkov, aws-cli, terraform) at runtime.
  • Evidence: SKILL.md and references/command-syntax.md demonstrate declaring tool dependencies with version ranges (e.g., checkov: "latest", terraform: "^1.10.0") which are resolved and installed by the underlying Atmos toolchain before command execution.
  • [COMMAND_EXECUTION]: The primary purpose of the skill is to facilitate the definition and execution of custom CLI commands that wrap shell scripts and Atmos operations.
  • Evidence: The steps field in the command definition schema supports type: shell, type: exec, and type: atmos, all of which involve spawning subprocesses to run potentially sensitive operations within the user's project environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:18 AM
Security Audit — agent-trust-hub — atmos-custom-commands