atmos-stacks
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the
!execYAML function, which enables the execution of arbitrary shell commands within stack configuration manifests as described inSKILL.md. - [EXTERNAL_DOWNLOADS]: Documentation in
references/import-patterns.mddetails support for remote configuration imports via Git, S3, GCS, OCI, and HTTP/HTTPS protocols, allowing content to be fetched from external network sources. - [DYNAMIC_EXECUTION]: The skill describes extensive support for Go templates and Sprig functions in imported YAML files, allowing for dynamic content generation at runtime based on external context variables.
- [INDIRECT_PROMPT_INJECTION]: The skill documents a surface for indirect prompt injection via multiple data ingestion points that lack explicit sanitization. 1. Ingestion points:
!terraform.output,!env,!store, and remote imports (described inSKILL.mdandreferences/import-patterns.md). 2. Boundary markers: Absent. 3. Capability inventory:!execshell execution, lifecyclehookswith command execution, and componentcommandoverrides. 4. Sanitization: Absent.
Audit Metadata