skills/cloudposse/atmos/atmos-git/Gen Agent Trust Hub

atmos-git

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines various commands that wrap Git operations through the 'atmos' CLI tool, including cloning, committing, pushing, and managing local Git hook shims. These operations involve executing shell commands to interact with the local file system and remote repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external Git repositories. It documents a specific security control, the 'Fork-PR Trust Gate,' which is intended to prevent the execution of untrusted code from forked PRs in elevated CI contexts (like 'pull_request_target').
  • Ingestion points: Remote Git repositories specified via URI or CI environment variables.
  • Boundary markers: The 'Fork-PR Trust Gate' acts as a boundary by refusing to clone untrusted forks in sensitive CI events unless an explicit bypass is provided.
  • Capability inventory: The skill uses the 'atmos' CLI to perform file system operations, repository management, and hook execution.
  • Sanitization: The tool implements a trust gate that validates the source of the repository against the CI event context to mitigate 'pwn request' style attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:18 AM
Security Audit — agent-trust-hub — atmos-git