atmos-schemas
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a configuration system that ingests external YAML data, identifying a potential indirect injection surface.
- Ingestion points: Stack manifest files located in the
stacks/directory and CLI configuration files likeatmos.yaml. - Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions for data processed by the tool.
- Capability inventory: The skill notes support for Atmos-specific tags such as
!include,!import, and!env, and utilizes the Atmos CLI for validation. - Sanitization: No explicit content sanitization or escaping mechanisms are mentioned for the ingested data.
- [EXTERNAL_DOWNLOADS]: The skill defines resources that are downloaded from the vendor's infrastructure and well-known public registries.
- Evidence: Fetching schemas from
https://atmos.tools/schemas/atmos/atmos-manifest/1.0/atmos-manifest.jsonandhttps://json.schemastore.org/atmos-manifest.json. - Context: These downloads are standard operations for IDE auto-completion and configuration validation against official schemas.
Audit Metadata