Back to skill

Security audit

Atlas Admin Console

Security checks for vulnerabilities and agentic risk

Overview

The skill is an Atlas administration helper, but it asks for broad command and file authority while showing high-impact automation with weak scoping and incomplete packaged support.

Review before installing. Only use this skill in a controlled Atlas admin environment, with least-privilege API keys, explicit project or organization scope, dry runs where possible, and manual confirmation for cluster, user, IP allowlist, alert automation, Terraform, replay, or cross-organization changes. Do not let it generate credentials or CIDR allowlist entries from generic model context.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill uses very broad activation language like improving efficiency, automation, and workflow optimization, which can cause an agent to invoke a high-privilege Atlas administration skill for vague generic requests. In context, this is dangerous because the skill exposes read, write, and exec capabilities and describes bulk API and infrastructure operations, raising the chance of overbroad or unintended privileged actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The markdown advertises file-writing, command execution, cluster provisioning, workflow automation, alert-triggered actions, and Terraform changes without prominent user-facing warnings about destructive impact, side effects, or approval requirements. In an Atlas admin context, this materially increases the risk of accidental infrastructure changes, credential exposure through exports, or unsafe automated responses across multiple projects and organizations.

Ssd 3

Medium
Confidence
96% confidence
Finding
The workflow example appears to populate sensitive fields such as database usernames, passwords, and IP allowlist entries from contextual or generated placeholders like console_metadata, console_status, and console_summary. This is dangerous because it normalizes unsafe binding of untrusted context into credentials and network access controls, which could lead to weak credentials, accidental secret disclosure, or unauthorized exposure via malformed allowlist entries.

Static analysis

No suspicious patterns detected.