tigris-sdk-guide
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to automatically check for and install the Tigris CLI using
npm install -g @tigrisdata/cliif the tool is not found on the system (SKILL.md). - [EXTERNAL_DOWNLOADS]: The skill references and guides the installation of several external packages from public registries to interact with the Tigris platform, including
@tigrisdata/storagefrom npm,tigris-boto3-extfrom PyPI, andgithub.com/tigrisdata/storage-govia Go modules. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user queries about cloud storage configuration (SKILL.md). Evidence Chain: 1. Ingestion points: User prompts regarding SDK selection and framework setup. 2. Boundary markers: Absent. 3. Capability inventory: Includes shell command execution (npm install) and library installation across multiple package managers. 4. Sanitization: The skill does not provide explicit mechanisms for sanitizing user-provided environment or project data before processing.
Audit Metadata