atmos-devcontainer

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill documentation provides examples for mounting sensitive host credential directories into the container environment. Evidence: SKILL.md contains bind-mount configurations for ${HOME}/.aws and ${HOME}/.ssh.
  • [PRIVILEGE_ESCALATION]: The skill facilitates the creation of containers with host-level privileges. Evidence: SKILL.md and references/commands-reference.md explicitly document the --privileged runtime argument and the remoteUser: "root" setting.
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture ingests external configuration data, creating a potential attack surface. Ingestion points: SKILL.md documents importing .devcontainer/devcontainer.json files via the !include tag. Boundary markers: Absent. Capability inventory: The skill can execute commands in the container (exec), mount local filesystems, and control container lifecycles. Sanitization: Absent; the skill ignores unsupported fields but does not explicitly validate the contents of supported fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-devcontainer