atmos-workflows

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute arbitrary shell and Atmos commands defined within workflow steps.
  • Evidence: Use of type: shell, type: exec, and type: atmos in SKILL.md and references/workflow-syntax.md.
  • Evidence: Example commands like terraform deploy vpc, aws sts get-caller-identity, and ./scripts/check-prod.sh.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and installing external tools and resources.
  • Evidence: The dependencies field in SKILL.md and references/workflow-syntax.md allows for the automated installation of tools such as terraform, kubectl, and checkov via atmos-toolchain.
  • Evidence: A shell step example in references/workflow-syntax.md uses wget https://example.com/file.tar.gz to download a remote archive.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where instructions embedded in workflow data files could influence agent behavior.
  • Ingestion points: The skill reads workflow definitions from YAML files located in the stacks/workflows/ directory, as specified in SKILL.md.
  • Boundary markers: No explicit boundary markers or "ignore embedded instructions" warnings were found in the provided documentation.
  • Capability inventory: The skill has high privileges, including shell execution (type: shell), cloud authentication (identity), and the ability to install arbitrary tools (dependencies).
  • Sanitization: No evidence of sanitization or validation of the content within the workflow files before execution was identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:35 AM
Security Audit — agent-trust-hub — atmos-workflows