atmos-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute arbitrary shell and Atmos commands defined within workflow steps.
- Evidence: Use of
type: shell,type: exec, andtype: atmosinSKILL.mdandreferences/workflow-syntax.md. - Evidence: Example commands like
terraform deploy vpc,aws sts get-caller-identity, and./scripts/check-prod.sh. - [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and installing external tools and resources.
- Evidence: The
dependenciesfield inSKILL.mdandreferences/workflow-syntax.mdallows for the automated installation of tools such asterraform,kubectl, andcheckovviaatmos-toolchain. - Evidence: A shell step example in
references/workflow-syntax.mduseswget https://example.com/file.tar.gzto download a remote archive. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where instructions embedded in workflow data files could influence agent behavior.
- Ingestion points: The skill reads workflow definitions from YAML files located in the
stacks/workflows/directory, as specified inSKILL.md. - Boundary markers: No explicit boundary markers or "ignore embedded instructions" warnings were found in the provided documentation.
- Capability inventory: The skill has high privileges, including shell execution (
type: shell), cloud authentication (identity), and the ability to install arbitrary tools (dependencies). - Sanitization: No evidence of sanitization or validation of the content within the workflow files before execution was identified.
Audit Metadata