atmos-toolchain

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading binary artifacts from external sources, primarily through the Aqua registry on GitHub (https://github.com/aquaproj/aqua-registry) and other user-defined HTTP or GitHub release URLs.
  • [REMOTE_CODE_EXECUTION]: The instructions enable the agent to install and run third-party binaries using the atmos toolchain install and atmos toolchain exec commands, which involves executing code downloaded from remote registries.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage tools, search registries, and execute binaries within the agent's execution environment.
  • [PERSISTENCE]: The skill suggests adding evaluation hooks to shell profile files (such as .bashrc or .zshrc) via the atmos toolchain env command to ensure toolchain paths are maintained across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on parsing configuration files within the repository, such as atmos.yaml, .tool-versions, and stack YAML files (e.g., dependencies.tools), to determine which tools to install and execute. This represents an attack surface where a malicious configuration file could be used to trigger the installation of unauthorized or compromised software.
  • Ingestion points: atmos.yaml, .tool-versions, and stack YAML files containing dependencies.tools definitions.
  • Boundary markers: No explicit delimiters or warnings are specified for the ingestion of these configuration files.
  • Capability inventory: Network file downloads (toolchain install), file system writes to installation directories, and arbitrary binary execution (toolchain exec).
  • Sanitization: The skill documents optional checksum and signature verification settings (e.g., verification: checksums: when_available) as a security feature.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:35 AM
Security Audit — agent-trust-hub — atmos-toolchain