skills/cloudposse/atmos/atmos-pro/Gen Agent Trust Hub

atmos-pro

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains instructional content for configuring Atmos Pro workflows. No malicious patterns, obfuscation, or unauthorized data access were detected. The documentation encourages secure practices such as using GitHub OIDC tokens instead of static API keys for CI/CD authentication.
  • [COMMAND_EXECUTION]: The skill documents standard CLI commands for the atmos tool, such as atmos describe affected --upload and atmos pro commit. These are used for intended infrastructure management operations (uploading affected stacks, locking components, and committing changes via a GitHub App) and do not represent a security risk within the context of the tool's purpose.
  • [DATA_EXFILTRATION]: The skill describes the transmission of infrastructure metadata, such as component instance inventory and plan status, to the Atmos Pro control plane. This is a primary functionality of the service for enabling visibility and drift detection. The resources involved (Atmos Pro, Atmos CLI) are part of the vendor's ecosystem, and no unauthorized or suspicious external data transfers were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:52 AM
Security Audit — agent-trust-hub — atmos-pro