atmos-packer
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from stack manifests and build metadata, creating a surface for indirect prompt injection.\n * Ingestion points: Reads configuration from YAML stack manifests (
vars,env) and build artifacts from Packer manifest JSON files.\n * Boundary markers: Absent; the skill does not provide instructions to the agent to treat embedded strings in manifests as data rather than instructions.\n * Capability inventory: The skill can execute Packer commands which include shell provisioners, and it can create or modify local files such as variable files.\n * Sanitization: There is no mention of filtering or validating manifest content before processing it for use in build commands.\n- [EXTERNAL_DOWNLOADS]: The skill supports Just-In-Time (JIT) vendoring to download Packer templates from remote URIs.\n * Fetches configuration from the vendor's GitHub repository:github.com/cloudposse/packer-templates.\n * Supports Git, S3, OCI, and HTTP protocols for remote template acquisition.\n- [COMMAND_EXECUTION]: The skill invokes external command-line utilities for orchestration and data processing.\n * Executes the Packer CLI for image creation, template validation, and initialization.\n * Usesyqfor querying and filtering Packer manifest data.\n * Performs filesystem operations such as directory deletion via thesource deletecommand.
Audit Metadata