tigris-security-access-control

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the official Tigris CLI package (@tigrisdata/cli) from the npm registry if it is not already available on the system.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell commands via the tigris CLI to perform administrative tasks such as creating access keys, configuring CORS rules, and managing bucket permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes user-provided inputs like bucket names, file paths, and CORS configuration files which are then interpolated into CLI commands.
  • Ingestion points: User-supplied bucket names, environment variables, and local configuration files (cors.json) processed in SKILL.md and README.md.
  • Boundary markers: None present; the skill relies on standard bash command execution patterns.
  • Capability inventory: The skill has the capability to execute shell commands (tigris), install packages (npm), and read/write local files (curl, cp).
  • Sanitization: No explicit sanitization or validation of user-provided bucket names or configuration content is defined within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — tigris-security-access-control