skills/cloudposse/atmos/atmos-steps/Gen Agent Trust Hub

atmos-steps

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to create steps that read and process file content (e.g., using pathlib.Path().read_text() in a script step). This creates a surface where malicious data within those files could influence agent behavior or script logic.\n
  • Ingestion points: type: script logic and type: workdir sources.\n
  • Boundary markers: None explicitly defined in the provided DSL examples.\n
  • Capability inventory: The DSL includes shell, script, exec, atmos, and http handlers.\n
  • Sanitization: No specific sanitization or validation logic is prescribed for data ingested from files.\n- [DYNAMIC_EXECUTION]: The skill facilitates dynamic execution through the type: script handler, which allows for inline scripts to be run via an interpreter (e.g., python3). This is a core feature of the automation DSL but represents a capability that must be used with caution when processing external inputs.\n- [COMMAND_EXECUTION]: The DSL provides native support for running shell commands (type: shell), system execution (type: exec), and tool-specific commands (type: atmos). These handlers grant the agent the ability to interact directly with the operating system and installed tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-steps