tigris-object-operations
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the official Tigris CLI (
@tigrisdata/cli) from the public npm registry, which is a standard procedure for enabling the platform's functionality. - [COMMAND_EXECUTION]: The skill performs shell command execution to verify the installation of the Tigris CLI and to install it if it is missing.
- [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to download content from Tigris Storage, which introduces a surface for indirect prompt injection if the agent processes the retrieved data.
- Ingestion points: Objects and files retrieved from storage via the
getfunction. - Boundary markers: No explicit delimiters are used to separate user data from instructions in the retrieved content.
- Capability inventory: The agent has the capability to execute shell commands and perform network operations.
- Sanitization: There are no built-in sanitization routines to validate or escape data fetched from remote buckets before the agent interacts with it.
Audit Metadata