atmos-templates
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the use of
atmos.GomplateDatasourceto fetch data from external network locations, such ashttps://api.ipify.org?format=json. While this is a well-known service, it represents a mechanism for the agent to perform outbound network requests at runtime. - [DATA_EXFILTRATION]: The skill details methods for accessing sensitive system information and credentials through various functions:
env "USER"andenv "HOME"are used to retrieve environment variables.atmos.Storeandatmos.GomplateDatasourceare demonstrated fetching secrets from providers like AWS SSM (aws+smp://) and HashiCorp Vault..env.*context variables provide access to all environment variables available to the process.- [COMMAND_EXECUTION]: The
atmos.Componentfunction is documented as a way to read configurations and outputs from other components. The documentation notes that this may involve initializing Terraform and runningterraform output, which constitutes indirect command execution initiated by the templating engine. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes data from untrusted or external sources that are then interpolated into the agent's context:
- Ingestion points: External data is ingested via
atmos.GomplateDatasource(APIs, files, remote secret stores) and component variables (.vars.*). - Boundary markers: The templates use standard
{{ }}delimiters and the documentation recommends quoting values in YAML to prevent parsing errors. Escaping techniques like!literalor backticks are suggested for passing templates to external systems. - Capability inventory: The templating engine can perform network requests, access environment variables, read from secret stores, and trigger Terraform operations via
atmos.Component. - Sanitization: The documentation mentions using
toJsonortoRawJsonfor handling complex types but does not detail specific sanitization or validation of the content fetched from external datasources before it is evaluated by the Go template engine.
Audit Metadata