tigris-sdk-guide

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to automatically check for and install the Tigris CLI using npm install -g @tigrisdata/cli if the tool is not found on the system (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: The skill references and guides the installation of several external packages from public registries to interact with the Tigris platform, including @tigrisdata/storage from npm, tigris-boto3-ext from PyPI, and github.com/tigrisdata/storage-go via Go modules.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user queries about cloud storage configuration (SKILL.md). Evidence Chain: 1. Ingestion points: User prompts regarding SDK selection and framework setup. 2. Boundary markers: Absent. 3. Capability inventory: Includes shell command execution (npm install) and library installation across multiple package managers. 4. Sanitization: The skill does not provide explicit mechanisms for sanitizing user-provided environment or project data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — tigris-sdk-guide