skills/cloudposse/atmos/atmos-helm/Gen Agent Trust Hub

atmos-helm

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by facilitating the processing of external data from third-party Helm charts and repositories.\n
  • Ingestion points: The agent is instructed to fetch and process Helm charts from local paths, remote HTTP repositories, and OCI registries defined in stack manifests (SKILL.md).\n
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for the agent when processing downloaded chart content or value files.\n
  • Capability inventory: The skill provides the agent with the ability to execute atmos helm apply and atmos helm deploy, which perform state-changing operations on Kubernetes clusters and Git repositories (SKILL.md).\n
  • Sanitization: No explicit sanitization or strict schema validation steps for external chart content are described before the resources are applied to a target.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of external components and binaries.\n
  • It references fetching Helm charts from remote repositories, including standard community sources like the Prometheus Community repository.\n
  • It documents the ability to install external Helm CLI plugins via the atmos helm plugin install command.\n- [COMMAND_EXECUTION]: The skill involves executing Helm-related operations that interact with sensitive infrastructure.\n
  • It utilizes the Helm Go SDK to template, diff, and apply Kubernetes resources directly to clusters.\n
  • It supports delivery to Git deployment repositories, involving git operations such as cloning and committing rendered manifests.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-helm