atmos-init
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill describes the capability of the
atmos initcommand to fetch project templates from various remote sources. - Evidence includes support for template sources via Git, S3 buckets, OCI registries, and HTTPS URLs.
- [COMMAND_EXECUTION]: The tool documented in this skill supports the execution of lifecycle hooks during the project bootstrapping process.
- These hooks are defined in the template manifest under
spec.hooksand support the execution of sequences of steps. - [DYNAMIC_EXECUTION]: The skill documents the use of the Common Expression Language (CEL) within templates to handle conditional logic for fields and files.
- The
when:predicates in template manifests allow for dynamic evaluation of expressions over user-provided answers at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface where the agent processes external, potentially untrusted data that can influence its behavior.
- Ingestion points: Remote project templates fetched via Git, S3, OCI, or HTTPS as described in
SKILL.md. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are documented for the template ingestion process.
- Capability inventory: The
atmosCLI, as used by the agent, can perform file system writes and execute shell commands through thespec.hooksmechanism. - Sanitization: No explicit sanitization or validation of the remote template content is mentioned; the security of the operation depends on the user's trust in the template source.
Audit Metadata