atmos-migration

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to facilitate the migration of external repository content (such as Makefiles, Taskfiles, and Terraform modules) into Atmos configurations, which creates an inherent ingestion surface for untrusted data.
  • Ingestion points: Project files including Makefile, Justfile, Taskfile.yml, aqua.yaml, and .tf files identified during the migration process.
  • Boundary markers: The skill instructs the agent to use explicit Atmos YAML tags (e.g., !include, !terraform.state) to manage data boundaries and provides guidance on mapping logic to structured YAML.
  • Capability inventory: The generated configurations involve shell command execution via type: shell steps and automated file generation for backends and variables.
  • Sanitization: The instructions favor the use of Atmos YAML functions for their type safety and error handling over general-purpose datasources or raw templates.
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions for installing toolchains and components from external sources, all of which target official or well-known entities.
  • Evidence: References to the Aqua registry (github.com/aquaproj/aqua-registry) in references/from-aqua.md and the official Atmos container image (ghcr.io/cloudposse/atmos) in references/from-component-updater.md.
  • Context: These downloads are fundamental to the tool's operation and target established registries and vendor repositories.
  • [COMMAND_EXECUTION]: The migration process involves defining custom commands that execute shell scripts and external binaries as part of task-runner adoption.
  • Evidence: The skill guides the agent in creating type: shell and type: atmos steps in atmos.yaml to replace legacy task runner targets.
  • Context: This is the core functionality of the skill, and the instructions focus on preserving existing execution semantics while providing a migration path to the new orchestrator.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-migration