atmos-modernization

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides examples for using standard Atmos CLI commands such as atmos terraform plan. These are legitimate and expected for managing infrastructure as code.
  • [EXTERNAL_DOWNLOADS]: The instructions refer to official resources including the Atmos Docker image (ghcr.io/cloudposse/atmos) and GitHub repositories within the cloudposse and cloudposse-terraform-components organizations. These are recognized as official vendor-controlled resources.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill actively promotes improved security by instructing users to migrate away from legacy patterns like static GitHub tokens and raw secret store calls, recommending the use of Atmos Auth and the !secret tag for declarative secret management.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes stack configuration and uses YAML functions like !terraform.output to interpolate data, this is a standard operational feature of the Atmos toolset. The skill provides guidance on correct quoting to ensure predictable parsing of these expressions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 01:04 AM
Security Audit — agent-trust-hub — atmos-modernization