skills/cloudposse/atmos/atmos-stacks/Gen Agent Trust Hub

atmos-stacks

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the !exec YAML function, which enables the execution of arbitrary shell commands within stack configuration manifests as described in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: Documentation in references/import-patterns.md details support for remote configuration imports via Git, S3, GCS, OCI, and HTTP/HTTPS protocols, allowing content to be fetched from external network sources.
  • [DYNAMIC_EXECUTION]: The skill describes extensive support for Go templates and Sprig functions in imported YAML files, allowing for dynamic content generation at runtime based on external context variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a surface for indirect prompt injection via multiple data ingestion points that lack explicit sanitization. 1. Ingestion points: !terraform.output, !env, !store, and remote imports (described in SKILL.md and references/import-patterns.md). 2. Boundary markers: Absent. 3. Capability inventory: !exec shell execution, lifecycle hooks with command execution, and component command overrides. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:34 AM
Security Audit — agent-trust-hub — atmos-stacks