atmos-terraform
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches Terraform modules from public GitHub repositories, such as those under the
cloudposse-terraform-componentsorganization, during component provisioning operations. - [REMOTE_CODE_EXECUTION]: The Atmos toolchain downloads and installs specific versions of Terraform and OpenTofu binaries from official distribution points to ensure environment consistency across development and CI/CD systems.
- [COMMAND_EXECUTION]: The skill wraps the Terraform and OpenTofu CLI binaries to execute infrastructure lifecycle commands, including
plan,apply,deploy, anddestroyacross one or more stacks. - [DYNAMIC_EXECUTION]: The skill processes Go templates and YAML functions within stack configuration manifests to dynamically generate
backend.tf.jsonandterraform.tfvars.jsonfiles before binary execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes external configuration data from stack manifests, Git commit history, and remote component source URLs, which represents a potential attack surface for indirect influence on agent behavior.
- Ingestion points: Stack manifests (
atmos.yamland stack YAML files), Git repository state (used for identifying affected components), and remote module source URLs. - Boundary markers: No explicit delimiters or instructional constraints are defined to isolate untrusted configuration data from the execution logic during template interpolation.
- Capability inventory: The skill performs file system writes (
SKILL.md), shell command execution (SKILL.md), and network operations for module and binary acquisition (SKILL.md,references/toolchain-pinning.md). - Sanitization: No explicit sanitization, validation, or escaping logic for variables interpolated into configuration files is described.
Audit Metadata