file-storage

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of untrusted data through its file upload and download functions.
  • Ingestion points: The put, get, and handleClientUpload functions in SKILL.md and framework-specific resource files (e.g., express.md, nextjs.md) process data provided by external callers.
  • Boundary markers: The skill does not provide specific instructions for agents to use boundary markers or delimiters when processing or summarizing the contents of files retrieved via the storage SDK.
  • Capability inventory: The skill provides methods for file-write (put), file-read (get), and network-based upload operations, which could be misused if an agent is tricked via malicious content in a processed file.
  • Sanitization: While the skill emphasizes checking error codes and using private access roles, it does not explicitly describe sanitization of file contents or paths before processing.- [EXTERNAL_DOWNLOADS]: Fetches the Tigris CLI and SDK from the official NPM registry.
  • Evidence: The skill instructs users to install packages using npm install -g @tigrisdata/cli and npm install @tigrisdata/storage in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — file-storage