atmos-stores
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines configuration and usage patterns for Atmos external stores. No malicious patterns such as prompt injection, unauthorized exfiltration, or obfuscation were detected. All described behaviors are consistent with the intended purpose of configuration and data sharing within the Atmos framework.
- [INDIRECT_PROMPT_INJECTION]: The skill describes mechanisms for ingesting data from external backends into component configurations via
!storeand!store.getfunctions. While this creates a surface for indirect prompt injection if an external store is compromised, the skill provides architectural guidance on scoping and default values. This is a characteristic of the underlying Atmos platform rather than a malicious finding in the skill itself. - [CREDENTIALS_UNSAFE]: The skill demonstrates best practices for credential handling by encouraging the use of environment variables (e.g.,
!env ARTIFACTORY_ACCESS_TOKEN) and identity-based authentication. Examples involving credentials use obvious placeholders (e.g.,...orpassword) rather than hardcoded secrets.
Audit Metadata