atmos-validation

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the atmos CLI to perform validation of configurations, stacks, and components. These are standard operations for the tool's intended purpose.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external JSON schemas from https://json.schemastore.org for validating GitHub Actions workflows. This is a well-known and reputable service for schema definitions.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill processes various Atmos configuration files (atmos.yaml), stack manifests, and component variables (input.vars) in SKILL.md and references/project-validation.md.
  • Boundary markers: No explicit natural language boundary markers or "ignore instructions" warnings are defined for the processed data; it relies on the internal parsing logic of the Atmos tool.
  • Capability inventory: The skill possesses the capability to execute shell commands (atmos) and perform network requests to download schemas.
  • Sanitization: Input data is sanitized and validated against structural rules (JSON Schema) and business logic (OPA/Rego) as defined in references/json-schema.md and references/opa-policies.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:36 AM
Security Audit — agent-trust-hub — atmos-validation