atlas-cloud

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the 'atlascloud-mcp' tool using 'npx', which is a standard method for distributing MCP (Model Context Protocol) servers. It also references well-known libraries such as 'openai' and 'requests' in its implementation templates.
  • [DATA_EXFILTRATION]: The skill includes a dedicated tool ('atlas_upload_media') and code templates designed to upload local files to the vendor's cloud storage (Aliyun OSS). While this involves reading local data and sending it to a remote server, it is a documented core feature required for image-to-video and image-editing workflows provided by the service.
  • [COMMAND_EXECUTION]: Multiple reference files provide cURL command templates for shell environments. These are standard developer tools for API interaction and do not contain malicious patterns or obfuscation.
  • [PROMPT_INJECTION]: The documentation mentions an 'unrestricted' workflow with 'looser guardrails' available on the vendor's website. This refers to the service's own content moderation policies for media generation and does not attempt to override the AI agent's internal safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 12:47 AM