atmos-helmfile

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill implements a Just-In-Time (JIT) vendoring system that downloads Helmfile components from remote URIs. Supported protocols include Git, S3, HTTP, GCS, and OCI. Examples include the vendor's own GitHub repositories.\n- [REMOTE_CODE_EXECUTION]: Remote resources fetched via the JIT provisioner are executed as configuration logic by the Helmfile CLI during deployment commands like apply or sync.\n- [COMMAND_EXECUTION]: The skill invokes CLI tools including helmfile and aws eks update-kubeconfig. It provides mechanisms to pass arbitrary global options and native flags directly to the shell commands via the -- delimiter.\n- [DYNAMIC_EXECUTION]: Component logic is dynamically loaded and executed based on remote URIs and configuration paths computed at runtime.\n- [INDIRECT_PROMPT_INJECTION]: The tool's behavior is directed by external YAML stack manifests which define source URIs, environment variables, and component parameters.\n
  • Ingestion points: Stack manifests (e.g., stacks/dev.yaml, stacks/prod.yaml, stacks/catalog/ingress-nginx/defaults.yaml).\n
  • Boundary markers: None identified in the provided documentation.\n
  • Capability inventory: Shell command execution (helmfile, aws eks update-kubeconfig in SKILL.md), remote content fetching (go-getter in SKILL.md), and local variable file generation (SKILL.md).\n
  • Sanitization: No mention of content validation or sanitization for ingested configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-helmfile