skills/cloudposse/atmos/atmos-schemas/Gen Agent Trust Hub

atmos-schemas

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a configuration system that ingests external YAML data, identifying a potential indirect injection surface.
  • Ingestion points: Stack manifest files located in the stacks/ directory and CLI configuration files like atmos.yaml.
  • Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions for data processed by the tool.
  • Capability inventory: The skill notes support for Atmos-specific tags such as !include, !import, and !env, and utilizes the Atmos CLI for validation.
  • Sanitization: No explicit content sanitization or escaping mechanisms are mentioned for the ingested data.
  • [EXTERNAL_DOWNLOADS]: The skill defines resources that are downloaded from the vendor's infrastructure and well-known public registries.
  • Evidence: Fetching schemas from https://atmos.tools/schemas/atmos/atmos-manifest/1.0/atmos-manifest.json and https://json.schemastore.org/atmos-manifest.json.
  • Context: These downloads are standard operations for IDE auto-completion and configuration validation against official schemas.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-schemas