atmos-yaml-functions
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The
!execYAML function allows for the execution of arbitrary shell scripts directly from within YAML manifests. The skill documentation describes support for single-line and multi-line scripts, which are executed using a POSIX-compatible interpreter. - [EXTERNAL_DOWNLOADS]: The
!includefunction enables fetching configuration or text data from a wide variety of remote sources. Supported protocols include HTTPS, GitHub (github://), S3 (s3::), GCS (gcs::), SCP/SFTP, and OCI registries, allowing the inclusion of content from external networks. - [CREDENTIALS_UNSAFE]: The skill provides numerous primitives for accessing highly sensitive data environments. This includes
!secretfor managed secret backends,!envfor environment variables,!terraform.statefor reading infrastructure outputs directly from state files, and several!aws.*functions (like!aws.account_idand!aws.organization_id) that query identity and organization metadata via AWS APIs. - [DYNAMIC_EXECUTION]: The skill facilitates runtime logic execution through the
!templatefunction, which evaluates Go template expressions, and the!execfunction, which runs shell commands to generate YAML values dynamically during stack processing. - [DATA_EXFILTRATION]: The combination of data-access functions (like
!secret,!env, and!terraform.state) and network-capable functions (like!includetargeting remote URLs) creates a potential chain for exfiltrating sensitive infrastructure metadata to external servers if manifest contents are manipulated. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface where malicious instructions could be embedded in the data it processes.
- Ingestion points: Atmos stack manifest files (YAML) containing the custom tags described in the skill.
- Boundary markers: The documentation does not specify the use of delimiters or warnings to ignore instructions embedded within the arguments of functions like
!execor!template. - Capability inventory: Full shell execution (
!exec), remote file retrieval (!include), template evaluation (!template), and broad access to environment/infrastructure secrets. - Sanitization: There is no evidence of input validation or sanitization for values passed to the YAML functions before they are executed or interpolated.
Audit Metadata