skills/cloudposse/atmos/atmos-secrets/Gen Agent Trust Hub

atmos-secrets

Warn

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides the atmos secret exec and atmos secret shell commands. These features allow for the execution of arbitrary user-supplied commands or interactive shells with sensitive environment variables (secrets) automatically populated by the Atmos tool. This represents a significant capability for dynamic command execution using high-privilege credentials.\n- [DATA_EXFILTRATION]: Commands such as atmos secret pull and atmos secret get allow for the retrieval and local storage of secrets from remote backends (such as AWS SSM, Secrets Manager, or HashiCorp Vault). While intended for secret management, these tools can be leveraged to move sensitive data out of secure cloud providers into the local execution environment or to other remote destinations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external secret backends and declarative YAML configuration files, creating a surface for indirect injection attacks.\n
  • Ingestion points: Secret values retrieved from backends like AWS, Vault, or 1Password, and secret metadata defined in declarative YAML files (SKILL.md).\n
  • Boundary markers: None identified; the instructions do not specify how to delimit secret data from command logic during injection into execution contexts.\n
  • Capability inventory: Includes arbitrary command execution (exec), shell access, network synchronization with cloud backends, and file system writes (pull).\n
  • Sanitization: Masking is provided for standard display output, but no explicit validation or sanitization of secret content is described before it is injected into executable shells or command strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 25, 2026, 06:53 AM
Security Audit — agent-trust-hub — atmos-secrets