skills/cloudposse/atmos/atmos-packer/Gen Agent Trust Hub

atmos-packer

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from stack manifests and build metadata, creating a surface for indirect prompt injection.\n * Ingestion points: Reads configuration from YAML stack manifests (vars, env) and build artifacts from Packer manifest JSON files.\n * Boundary markers: Absent; the skill does not provide instructions to the agent to treat embedded strings in manifests as data rather than instructions.\n * Capability inventory: The skill can execute Packer commands which include shell provisioners, and it can create or modify local files such as variable files.\n * Sanitization: There is no mention of filtering or validating manifest content before processing it for use in build commands.\n- [EXTERNAL_DOWNLOADS]: The skill supports Just-In-Time (JIT) vendoring to download Packer templates from remote URIs.\n * Fetches configuration from the vendor's GitHub repository: github.com/cloudposse/packer-templates.\n * Supports Git, S3, OCI, and HTTP protocols for remote template acquisition.\n- [COMMAND_EXECUTION]: The skill invokes external command-line utilities for orchestration and data processing.\n * Executes the Packer CLI for image creation, template validation, and initialization.\n * Uses yq for querying and filtering Packer manifest data.\n * Performs filesystem operations such as directory deletion via the source delete command.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-packer