atmos-secrets
Warn
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides the
atmos secret execandatmos secret shellcommands. These features allow for the execution of arbitrary user-supplied commands or interactive shells with sensitive environment variables (secrets) automatically populated by the Atmos tool. This represents a significant capability for dynamic command execution using high-privilege credentials.\n- [DATA_EXFILTRATION]: Commands such asatmos secret pullandatmos secret getallow for the retrieval and local storage of secrets from remote backends (such as AWS SSM, Secrets Manager, or HashiCorp Vault). While intended for secret management, these tools can be leveraged to move sensitive data out of secure cloud providers into the local execution environment or to other remote destinations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external secret backends and declarative YAML configuration files, creating a surface for indirect injection attacks.\n - Ingestion points: Secret values retrieved from backends like AWS, Vault, or 1Password, and secret metadata defined in declarative YAML files (SKILL.md).\n
- Boundary markers: None identified; the instructions do not specify how to delimit secret data from command logic during injection into execution contexts.\n
- Capability inventory: Includes arbitrary command execution (
exec), shell access, network synchronization with cloud backends, and file system writes (pull).\n - Sanitization: Masking is provided for standard display output, but no explicit validation or sanitization of secret content is described before it is injected into executable shells or command strings.
Audit Metadata