atmos-introspection

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Documents the tool's --upload flag available in commands like atmos describe affected and atmos list instances. This feature allows the transmission of analysis results, component lists, and stack metadata to external HTTP endpoints or the vendor's Atmos Pro API.
  • [DYNAMIC_EXECUTION]: Describes the tool's default behavior of processing Go templates and custom YAML functions (e.g., --process-templates, --process-functions) to resolve stack configurations, which involves dynamic evaluation of manifest data.
  • [INDIRECT_PROMPT_INJECTION]: Identifies an attack surface where the agent processes data from local files and Git metadata.
  • Ingestion points: Reads local atmos.yaml configuration, YAML stack manifests, and Git repository history/metadata.
  • Boundary markers: The instructions do not specify any delimiters or "ignore embedded instructions" warnings for the agent when processing the output of these commands.
  • Capability inventory: The tool includes file system access for reading manifests, network operations for cloning repositories with SSH keys (--ssh-key), dynamic template/function processing, and data uploading capabilities.
  • Sanitization: No instructions are provided for sanitizing or validating the configuration data before the agent incorporates it into its context or decision-making process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-introspection