atmos-scaffold
Warn
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a lifecycle hook system (before and after generation) that supports a
shelltype for executing arbitrary commands. - Evidence in
SKILL.md: Thespec.hooksconfiguration allows defining commands such asgit add .usingtype: shell. - Evidence in
references/scaffold-yaml-schema.md: Confirms thatkind: stephooks support theshelltype. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect injection because it is designed to fetch and process external, potentially untrusted templates that can define their own shell hooks and file-writing logic.
- Ingestion points: The skill fetches templates from remote sources including Git, HTTPS, S3, and OCI registries (e.g.,
SKILL.mdmentionsoci://ghcr.io/org/template:v1). - Boundary markers: The documentation provides the
--skip-hooksCLI flag andATMOS_SCAFFOLD_SKIP_HOOKSenvironment variable to allow users to bypass hook execution for untrusted runs. - Capability inventory: The skill has the capability to write files to the local file system and execute shell commands through hooks defined in the
scaffold.yamlfile (referenced inSKILL.mdandreferences/scaffold-yaml-schema.md). - Sanitization: There is no explicit documentation regarding the sanitization or validation of template variables (answers) before they are interpolated into shell command strings in hooks.
- [EXTERNAL_DOWNLOADS]: The skill downloads templates and configuration from external sources, including well-known services.
- Fetches OCI-based templates from GitHub Container Registry (
ghcr.io). - Supports fetching templates from Git repositories, S3 buckets, and HTTPS URLs.
- [DYNAMIC_EXECUTION]: The skill utilizes Go templates (Gomplate/Sprig) and Common Expression Language (CEL) for dynamic logic and content rendering.
- Uses CEL for conditional logic in
when:fields for both questionnaire prompts and file generation. - Uses Go templates for rendering file content, dynamic matrix generation paths, and computing field options.
Audit Metadata