Agent skill

Atmos Validation

by cloudposse in cloudposse/atmos

Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations

Apache-2.0Auto-check passedDevOps & Cloud

Install Atmos Validation

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-validation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-validation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-validation .claude/skills/atmos-validation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-validation
GitHub stars
1.4k
Token cost
~2.2k tokens
SKILL.md length
762 words
Files
4 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations

  • Tasks that involve CI/CD
  • SKILL.md covers Start with the Validation Target, Validation Commands, Affected Validation and… and Base Paths, plus 7 more sections
  • Reaches json.schemastore.org and json-schema.org

What it does

Atmos Validation is an agent skill from cloudposse/atmos. Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/json-schema.md`, `references/opa-policies.md` and `references/project-validation.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CI/CD

Example prompts

  • “/atmos-validation”

What it can do on your machine

Read from SKILL.md and the folder at commit bbe58a6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, bash, json and rego).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • json.schemastore.org
    • json-schema.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Validation loads about 2.2k tokens when it runs, and up to ~7.8k if it reads all its reference files. Until then it costs about 43 tokens; SKILL.md has 762 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit bbe58a6, republished under its Apache-2.0 licence (© cloudposse). 762 words, ~2,214 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-validation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
atmos-validation
description
Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.1.0
metadata.category
security
references
references/json-schema.md, references/opa-policies.md, references/project-validation.md

Atmos Validation Framework

Use this skill for every Atmos validation command and validation policy configuration: aggregate project validation, configuration and stack schemas, JSON Schema, OPA/Rego, EditorConfig, GitHub Actions workflows, affected-file selection, and native CI reporting.

For detailed JSON Schema examples, read references/json-schema.md. For OPA/Rego policy patterns, read references/opa-policies.md. For project-wide, affected, and CI validation behavior, read references/project-validation.md.

Start with the Validation Target

NeedCommand
Run every project validatoratmos validate
Validate only changed project inputsatmos validate --affected
Validate atmos.yamlatmos validate config or atmos config validate
Validate stack manifestsatmos validate stacks or atmos stack validate
Validate .editorconfig rulesatmos validate editorconfig
Lint GitHub Actions workflows with actionlintatmos ci validate or atmos validate ci
Validate arbitrary files against JSON Schemaatmos validate schema <key>
Validate resolved component inputatmos validate component <component> -s <stack>

Start with the narrowest command that matches the change. Use the aggregate command for a repository gate because it reports every applicable validator instead of stopping at the first one.

Validation Commands

shell
atmos validate component vpc -s plat-ue2-prod
atmos validate stacks
atmos validate schema github-actions
atmos validate --affected --format rich

atmos validate component validates a component in a stack using settings.validation or explicit --schema-path / --schema-type flags.

atmos validate stacks validates stack YAML syntax, imports, duplicate component definitions, and manifest schema compliance.

atmos validate schema <key> validates arbitrary files matched by a schemas.<key>.matches glob against a JSON Schema.

atmos validate aggregates configuration, stack, EditorConfig, and GitHub Actions validation when those project inputs exist. It is the preferred CI entry point for repository-wide validation.

Affected Validation and Exclusions

Use --affected to select repository inputs changed from the merge base. In GitHub pull requests, Atmos reads the PR base; locally, pass --base <ref> when the default base is not appropriate.

shell
atmos validate --affected --base origin/main --format rich
atmos config validate --affected
atmos stack validate --affected
atmos validate ci --affected

Use repeatable repository-relative glob exclusions to keep deliberately-invalid test fixtures out of production validation. --exclude works with the aggregate command and the config, stacks, schema, and GitHub Actions validators whether they run all inputs or only affected inputs.

shell
atmos validate --affected --exclude 'tests/fixtures/**' --format rich
atmos validate schema github-actions --exclude 'tests/fixtures/**'
atmos validate ci --exclude 'tests/fixtures/**'

Use slash-separated repository globs. Do not use an exclusion to hide a deployable project path; run intentional negative fixtures in a dedicated test or annotation E2E check instead.

atmos validate editorconfig --exclude is its established EditorConfig regular-expression flag, not the generic repository-glob exclusion. The aggregate command still applies its repository-glob --exclude before invoking the EditorConfig validator.

Base Paths

Configure validation schema base paths in atmos.yaml:

yaml
schemas:
  jsonschema:
    base_path: stacks/schemas/jsonschema
  opa:
    base_path: stacks/schemas/opa
  atmos:
    manifest: stacks/schemas/atmos/atmos-manifest/1.0/atmos-manifest.json

The cue, opa, and jsonschema keys under schemas are reserved for Atmos schema-path configuration. Do not use those names as generic atmos validate schema <key> entries.

Component Validation

Define component validation under settings.validation:

yaml
components:
  terraform:
    vpc:
      settings:
        validation:
          validate-vpc-jsonschema:
            schema_type: jsonschema
            schema_path: vpc/validate-vpc-component.json
          check-vpc-opa:
            schema_type: opa
            schema_path: vpc/validate-vpc-component.rego
            module_paths:
              - catalog/constants
            timeout: 10

Each validation step can define:

PropertyUse
schema_typejsonschema or opa
schema_pathPath relative to the matching schema base path
module_pathsOPA module paths
descriptionHuman-readable description
disabledSkip the step when true
timeoutTimeout in seconds

Generic File Validation

Use atmos validate schema for non-Atmos files, such as GitHub Actions workflows or Kubernetes manifests:

yaml
schemas:
  github-actions:
    schema: https://json.schemastore.org/github-workflow.json
    matches:
      - .github/workflows/*.yml
      - .github/workflows/*.yaml
shell
atmos validate schema github-actions
Show full SKILL.md (296 more words)Show less

JSON Schema

JSON Schema validates structure, required fields, types, patterns, enums, and ranges. Atmos passes the full resolved component configuration to component schemas, so schemas usually validate under vars, settings, env, backend, or metadata.

Minimal component schema:

json
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "type": "object",
  "properties": {
    "vars": {
      "type": "object",
      "required": ["region"],
      "properties": {
        "region": { "type": "string" }
      }
    }
  }
}

OPA/Rego

Atmos OPA policies use package atmos and collect validation errors in errors.

rego
package atmos

errors[message] {
  input.vars.stage == "prod"
  input.vars.map_public_ip_on_launch == true
  message = "Public IP mapping is not allowed in prod"
}

OPA input is the resolved component configuration. Common fields include input.vars, input.settings, input.env, input.backend, input.metadata, and Terraform CLI context fields available during plan/apply.

CI Guidance

Run validation early in CI with the Atmos container and direct Atmos commands:

yaml
jobs:
  validate:
    runs-on: ubuntu-latest
    container:
      image: ghcr.io/cloudposse/atmos:${{ vars.ATMOS_VERSION }}
    steps:
      - uses: actions/checkout@v6
      - run: atmos validate --affected --format rich --exclude 'tests/fixtures/**'

Enable native CI output in atmos.yaml when validation runs in CI:

yaml
ci:
  enabled: true
  annotations:
    enabled: true

With native CI enabled, aggregate validation writes an Atmos job summary, including passed, skipped, and failed validators. Findings from validators that support source annotations (including GitHub Actions/actionlint) emit GitHub Actions workflow commands; a successful validation stays visible through the green check and job summary rather than creating success annotations. Use --format rich for readable CI diagnostics. The actionlint SARIF format is intentionally side-effect free, so use it when a separate SARIF uploader owns annotations.

Do not reintroduce deprecated setup actions in new examples. Route broader Native CI workflow structure, event triggers, permissions, and actionlint annotation E2E tests to atmos-ci.

Routing

NeedSkill
Detailed JSON Schema patternsreferences/json-schema.md
Detailed OPA/Rego policy patternsreferences/opa-policies.md
Aggregate, affected, exclusions, and native CI behaviorreferences/project-validation.md
Atmos manifest JSON Schema and IDE completionatmos-schemas
Stack manifest structure and importsatmos-stacks
Component configuration and inheritanceatmos-components
Native CI validation workflowsatmos-ci

Guardrails

  • Prefer stack vars validation over ad hoc shell checks.
  • Keep reusable business rules in OPA modules or JSON Schema files, not inline in CI.
  • Do not validate against guessed stack names or component names; use atmos list or atmos describe first.
  • Keep policy messages actionable and name the field that should change.

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in agent-skills/skills/atmos-validation of cloudposse/atmos.

  • SKILL.md
  • references/json-schema.md
  • references/opa-policies.md
  • references/project-validation.md

Open the folder on GitHubat commit bbe58a6

Compare with similar skills

Atmos Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Validation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Validation this skillcloudposse/atmos1.4k—~2.2kAutomated safety check: PassApache-2.0
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Templatesbartstc/vite-ts-react-template12213 repos~1.9kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Templates

    bartstc/vite-ts-react-template

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.

    122 GitHub starsUsed in 13 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Atmos Validation

What does Atmos Validation do?

Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations. Atmos Validation is an agent skill from cloudposse/atmos.

When should I use Atmos Validation?

Atmos Validation fits situations like: tasks that involve CI/CD.

How do I install Atmos Validation in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-validation -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-validation in cloudposse/atmos) into .claude/skills/atmos-validation in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Validation in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-validation -a codex`. Or copy the skill folder (agent-skills/skills/atmos-validation in cloudposse/atmos) into .agents/skills/atmos-validation in your project. Codex loads it when a task matches its description.

Can I use Atmos Validation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-validation, .gemini/skills/atmos-validation, .github/skills/atmos-validation and .opencode/skills/atmos-validation in your project.

What does Atmos Validation need to run?

SKILL.md names no scripts, command-line tools or credentials: Atmos Validation is instructions for the agent only.

Does Atmos Validation access the network?

SKILL.md names 2 domains. In commands or code: json.schemastore.org and json-schema.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Atmos Validation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Atmos Validation use?

Atmos Validation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Validation use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.6k tokens, read only when the agent opens those files.

What are the alternatives to Atmos Validation?

Skills that share tags, products or a category with Atmos Validation: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Validation?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,395 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 7, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.