tigris-lifecycle-management
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the official
@tigrisdata/clipackage from the public npm registry to provide object storage management capabilities.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands via thetigrisCLI to perform bucket lifecycle operations such as setting, getting, and deleting rules.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs such as bucket names and JSON configuration files which are then interpolated into shell commands, creating a potential surface for injection.\n - Ingestion points: User-supplied bucket names and lifecycle configuration file paths used in
tigris buckets lifecycle setcommands (SKILL.md).\n - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the command templates.\n
- Capability inventory: Shell command execution via
tigrisCLI and object storage operations through the@tigrisdata/storagelibrary (SKILL.md).\n - Sanitization: No explicit input validation or sanitization routines are implemented within the skill instructions.
Audit Metadata