atmos-introspection
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Documents the tool's
--uploadflag available in commands likeatmos describe affectedandatmos list instances. This feature allows the transmission of analysis results, component lists, and stack metadata to external HTTP endpoints or the vendor's Atmos Pro API. - [DYNAMIC_EXECUTION]: Describes the tool's default behavior of processing Go templates and custom YAML functions (e.g.,
--process-templates,--process-functions) to resolve stack configurations, which involves dynamic evaluation of manifest data. - [INDIRECT_PROMPT_INJECTION]: Identifies an attack surface where the agent processes data from local files and Git metadata.
- Ingestion points: Reads local
atmos.yamlconfiguration, YAML stack manifests, and Git repository history/metadata. - Boundary markers: The instructions do not specify any delimiters or "ignore embedded instructions" warnings for the agent when processing the output of these commands.
- Capability inventory: The tool includes file system access for reading manifests, network operations for cloning repositories with SSH keys (
--ssh-key), dynamic template/function processing, and data uploading capabilities. - Sanitization: No instructions are provided for sanitizing or validating the configuration data before the agent incorporates it into its context or decision-making process.
Audit Metadata