atmos-yaml-functions

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The !exec YAML function allows for the execution of arbitrary shell scripts directly from within YAML manifests. The skill documentation describes support for single-line and multi-line scripts, which are executed using a POSIX-compatible interpreter.
  • [EXTERNAL_DOWNLOADS]: The !include function enables fetching configuration or text data from a wide variety of remote sources. Supported protocols include HTTPS, GitHub (github://), S3 (s3::), GCS (gcs::), SCP/SFTP, and OCI registries, allowing the inclusion of content from external networks.
  • [CREDENTIALS_UNSAFE]: The skill provides numerous primitives for accessing highly sensitive data environments. This includes !secret for managed secret backends, !env for environment variables, !terraform.state for reading infrastructure outputs directly from state files, and several !aws.* functions (like !aws.account_id and !aws.organization_id) that query identity and organization metadata via AWS APIs.
  • [DYNAMIC_EXECUTION]: The skill facilitates runtime logic execution through the !template function, which evaluates Go template expressions, and the !exec function, which runs shell commands to generate YAML values dynamically during stack processing.
  • [DATA_EXFILTRATION]: The combination of data-access functions (like !secret, !env, and !terraform.state) and network-capable functions (like !include targeting remote URLs) creates a potential chain for exfiltrating sensitive infrastructure metadata to external servers if manifest contents are manipulated.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface where malicious instructions could be embedded in the data it processes.
  • Ingestion points: Atmos stack manifest files (YAML) containing the custom tags described in the skill.
  • Boundary markers: The documentation does not specify the use of delimiters or warnings to ignore instructions embedded within the arguments of functions like !exec or !template.
  • Capability inventory: Full shell execution (!exec), remote file retrieval (!include), template evaluation (!template), and broad access to environment/infrastructure secrets.
  • Sanitization: There is no evidence of input validation or sanitization for values passed to the YAML functions before they are executed or interpolated.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:19 AM
Security Audit — agent-trust-hub — atmos-yaml-functions