tigris-s3-migration

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Tigris CLI and various language-specific SDKs from official package registries to enable migration functionality.\n
  • Evidence: Installation of @tigrisdata/cli and @tigrisdata/storage via npm in SKILL.md and resources/sdk-nodejs.md.\n
  • Evidence: Installation of tigris-boto3-ext via pip in resources/sdk-python.md.\n
  • Evidence: Usage of go get for github.com/tigrisdata/storage-go in resources/sdk-go.md.\n- [COMMAND_EXECUTION]: The skill contains numerous examples of shell commands for data migration using tigris, aws, gsutil, and az CLI tools.\n
  • Evidence: Commands for creating shadow buckets and synchronizing data between providers in SKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a process for ingesting and moving data from external cloud storage providers, which serves as a potential surface for indirect injection if that data contains instructions intended for the agent.\n
  • Ingestion points: Data migrated from S3, GCS, and Azure containers as described in SKILL.md.\n
  • Boundary markers: None mentioned.\n
  • Capability inventory: Shell command execution via migration CLIs and SDK integration in the agent's environment as described in SKILL.md and resources/.\n
  • Sanitization: No sanitization of the content being migrated is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — tigris-s3-migration