tigris-image-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting and processing user-uploaded binary data (images).
  • Ingestion points: File upload handlers in resources/express.md, resources/django.md, and resources/remix.md receive untrusted input from multer memory storage or formData streams.
  • Boundary markers: Not present in the generic code snippets provided.
  • Capability inventory: The skill uses the Tigris Storage SDK to write processed data to remote storage (put function) across all included framework examples.
  • Sanitization: Image validation and sanitization are handled by the underlying industry-standard libraries (Sharp, Pillow, Intervention Image) during the processing phase.
  • [EXTERNAL_DOWNLOADS]: The documentation references the installation of standard and well-known image processing libraries from official package registries (npm, PyPI, RubyGems, Composer).
  • Referenced packages include sharp, django-imagekit, intervention/image, and image_processing.
  • [DATA_EXFILTRATION]: The skill correctly uses the Tigris Storage service for image hosting and optimization. While it encourages the use of access: "public" for CDN delivery, this is documented as an intentional choice for public-facing assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — tigris-image-optimization