tigris-agent-kit
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and installs the official
@tigrisdata/cliand@tigrisdata/agent-kitpackages from the npm registry. - [COMMAND_EXECUTION]: Instructs the agent to execute shell commands for global package installation and CLI operations as part of the setup process.
- [PROMPT_INJECTION]: Documents an indirect prompt injection surface in event-driven coordination workflows.
- Ingestion points: Webhook payloads processed by agents as described in
resources/coordination.md. - Boundary markers: Includes implementation details for Bearer token authentication to secure webhook endpoints.
- Capability inventory: Full access to the Tigris SDK for object storage, bucket management, and IAM operations.
- Sanitization: Examples demonstrate standard JSON parsing of external data.
Audit Metadata