atmos-devcontainer
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill documentation provides examples for mounting sensitive host credential directories into the container environment. Evidence:
SKILL.mdcontains bind-mount configurations for${HOME}/.awsand${HOME}/.ssh. - [PRIVILEGE_ESCALATION]: The skill facilitates the creation of containers with host-level privileges. Evidence:
SKILL.mdandreferences/commands-reference.mdexplicitly document the--privilegedruntime argument and theremoteUser: "root"setting. - [INDIRECT_PROMPT_INJECTION]: The skill architecture ingests external configuration data, creating a potential attack surface. Ingestion points:
SKILL.mddocuments importing.devcontainer/devcontainer.jsonfiles via the!includetag. Boundary markers: Absent. Capability inventory: The skill can execute commands in the container (exec), mount local filesystems, and control container lifecycles. Sanitization: Absent; the skill ignores unsupported fields but does not explicitly validate the contents of supported fields.
Audit Metadata