atmos-tests
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for capturing external HTTP response data which is then passed to script and shell execution steps, creating a potential surface for indirect prompt injection.\n
- Ingestion points: Data is ingested from external endpoints using the
type: httpstep documented inreferences/patterns.md.\n - Boundary markers: The skill does not define explicit boundary markers for the ingested data, though it advises using environment variables for safer data handling.\n
- Capability inventory: The skill has access to
type: script(Python, Node.js),type: shell, andtype: containersteps, which allow for code and command execution.\n - Sanitization: Examples demonstrate using environment variables and structured JSON parsing to process input data, which reduces the risk of direct code injection compared to string interpolation.\n- [DYNAMIC_EXECUTION]: The skill enables the creation and execution of scripts at runtime to perform validation logic.\n
- The
type: scriptstep documented inSKILL.mdallows embedding Python or Node.js code directly within Atmos configuration files.\n - This execution is a primary function of the skill for performing integration and smoke tests.\n- [COMMAND_EXECUTION]: The skill supports executing arbitrary shell commands through the
type: shellstep.\n - The
references/patterns.mdfile shows examples of running local shell scripts like./tests/smoke.shto validate deployment status.
Audit Metadata