atmos-steps
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to create steps that read and process file content (e.g., using
pathlib.Path().read_text()in a script step). This creates a surface where malicious data within those files could influence agent behavior or script logic.\n - Ingestion points:
type: scriptlogic andtype: workdirsources.\n - Boundary markers: None explicitly defined in the provided DSL examples.\n
- Capability inventory: The DSL includes
shell,script,exec,atmos, andhttphandlers.\n - Sanitization: No specific sanitization or validation logic is prescribed for data ingested from files.\n- [DYNAMIC_EXECUTION]: The skill facilitates dynamic execution through the
type: scripthandler, which allows for inline scripts to be run via an interpreter (e.g.,python3). This is a core feature of the automation DSL but represents a capability that must be used with caution when processing external inputs.\n- [COMMAND_EXECUTION]: The DSL provides native support for running shell commands (type: shell), system execution (type: exec), and tool-specific commands (type: atmos). These handlers grant the agent the ability to interact directly with the operating system and installed tooling.
Audit Metadata