skills/cloudposse/atmos/atmos-sbom/Gen Agent Trust Hub

atmos-sbom

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of local CLI tools, specifically 'atmos', 'git', and 'terraform'. These commands are used to inspect project configuration and generate metadata for the SBOM, which is the primary and legitimate purpose of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes an example of a GitHub Actions workflow using 'cloudposse/atmos/actions/github-runtime@v1'. This is an official resource provided by the skill's author ('cloudposse') for setting up the runtime environment in a CI pipeline.
  • [SAFE]: The skill contains 'Safe Output Rules' which explicitly instruct the agent to prevent the inclusion of absolute filesystem paths, credentials, tokens, or signed URLs in the generated SBOM output, demonstrating a secure-by-default design posture.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:52 AM
Security Audit — agent-trust-hub — atmos-sbom