atmos-modernization
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides examples for using standard Atmos CLI commands such as
atmos terraform plan. These are legitimate and expected for managing infrastructure as code. - [EXTERNAL_DOWNLOADS]: The instructions refer to official resources including the Atmos Docker image (
ghcr.io/cloudposse/atmos) and GitHub repositories within thecloudposseandcloudposse-terraform-componentsorganizations. These are recognized as official vendor-controlled resources. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill actively promotes improved security by instructing users to migrate away from legacy patterns like static GitHub tokens and raw secret store calls, recommending the use of
Atmos Authand the!secrettag for declarative secret management. - [INDIRECT_PROMPT_INJECTION]: While the skill processes stack configuration and uses YAML functions like
!terraform.outputto interpolate data, this is a standard operational feature of the Atmos toolset. The skill provides guidance on correct quoting to ensure predictable parsing of these expressions.
Audit Metadata