atmos-templates

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of atmos.GomplateDatasource to fetch data from external network locations, such as https://api.ipify.org?format=json. While this is a well-known service, it represents a mechanism for the agent to perform outbound network requests at runtime.
  • [DATA_EXFILTRATION]: The skill details methods for accessing sensitive system information and credentials through various functions:
  • env "USER" and env "HOME" are used to retrieve environment variables.
  • atmos.Store and atmos.GomplateDatasource are demonstrated fetching secrets from providers like AWS SSM (aws+smp://) and HashiCorp Vault.
  • .env.* context variables provide access to all environment variables available to the process.
  • [COMMAND_EXECUTION]: The atmos.Component function is documented as a way to read configurations and outputs from other components. The documentation notes that this may involve initializing Terraform and running terraform output, which constitutes indirect command execution initiated by the templating engine.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes data from untrusted or external sources that are then interpolated into the agent's context:
  • Ingestion points: External data is ingested via atmos.GomplateDatasource (APIs, files, remote secret stores) and component variables (.vars.*).
  • Boundary markers: The templates use standard {{ }} delimiters and the documentation recommends quoting values in YAML to prevent parsing errors. Escaping techniques like !literal or backticks are suggested for passing templates to external systems.
  • Capability inventory: The templating engine can perform network requests, access environment variables, read from secret stores, and trigger Terraform operations via atmos.Component.
  • Sanitization: The documentation mentions using toJson or toRawJson for handling complex types but does not detail specific sanitization or validation of the content fetched from external datasources before it is evaluated by the Go template engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-templates