tigris-object-operations

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official Tigris CLI (@tigrisdata/cli) from the public npm registry, which is a standard procedure for enabling the platform's functionality.
  • [COMMAND_EXECUTION]: The skill performs shell command execution to verify the installation of the Tigris CLI and to install it if it is missing.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to download content from Tigris Storage, which introduces a surface for indirect prompt injection if the agent processes the retrieved data.
  • Ingestion points: Objects and files retrieved from storage via the get function.
  • Boundary markers: No explicit delimiters are used to separate user data from instructions in the retrieved content.
  • Capability inventory: The agent has the capability to execute shell commands and perform network operations.
  • Sanitization: There are no built-in sanitization routines to validate or escape data fetched from remote buckets before the agent interacts with it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — tigris-object-operations