tigris-security-access-control
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the official Tigris CLI package (
@tigrisdata/cli) from the npm registry if it is not already available on the system. - [COMMAND_EXECUTION]: The skill makes extensive use of shell commands via the
tigrisCLI to perform administrative tasks such as creating access keys, configuring CORS rules, and managing bucket permissions. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes user-provided inputs like bucket names, file paths, and CORS configuration files which are then interpolated into CLI commands.
- Ingestion points: User-supplied bucket names, environment variables, and local configuration files (
cors.json) processed inSKILL.mdandREADME.md. - Boundary markers: None present; the skill relies on standard bash command execution patterns.
- Capability inventory: The skill has the capability to execute shell commands (
tigris), install packages (npm), and read/write local files (curl,cp). - Sanitization: No explicit sanitization or validation of user-provided bucket names or configuration content is defined within the skill instructions.
Audit Metadata