atmos-validation
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
atmosCLI to perform validation of configurations, stacks, and components. These are standard operations for the tool's intended purpose. - [EXTERNAL_DOWNLOADS]: The skill fetches external JSON schemas from
https://json.schemastore.orgfor validating GitHub Actions workflows. This is a well-known and reputable service for schema definitions. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill processes various Atmos configuration files (
atmos.yaml), stack manifests, and component variables (input.vars) inSKILL.mdandreferences/project-validation.md. - Boundary markers: No explicit natural language boundary markers or "ignore instructions" warnings are defined for the processed data; it relies on the internal parsing logic of the Atmos tool.
- Capability inventory: The skill possesses the capability to execute shell commands (
atmos) and perform network requests to download schemas. - Sanitization: Input data is sanitized and validated against structural rules (JSON Schema) and business logic (OPA/Rego) as defined in
references/json-schema.mdandreferences/opa-policies.md.
Audit Metadata