atmos-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of
kind: commandandkind: step(such asshellorcontainertypes), which allow the execution of binaries and shell scripts during lifecycle events likebefore.terraform.planorafter.terraform.apply. - [EXTERNAL_DOWNLOADS]: The instructions describe how Atmos resolves and installs required binaries specified in
dependencies.toolsto ensure they are available on the system path for hook execution. - [INDIRECT_PROMPT_INJECTION]: The hook system supports conditional execution using CEL expressions that process runtime facts such as
stackandcomponentnames. 1. Ingestion points: Stack manifests and runtime metadata. 2. Boundary markers: The documentation does not specify explicit delimiters or sanitization for CEL expressions. 3. Capability inventory: The skill facilitates the execution of shell commands, containers, and infrastructure scanners. 4. Sanitization: Standard CEL evaluation is used without explicit mention of sanitization for user-provided configuration strings.
Audit Metadata