tigris-agent-kit

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the official @tigrisdata/cli and @tigrisdata/agent-kit packages from the npm registry.
  • [COMMAND_EXECUTION]: Instructs the agent to execute shell commands for global package installation and CLI operations as part of the setup process.
  • [PROMPT_INJECTION]: Documents an indirect prompt injection surface in event-driven coordination workflows.
  • Ingestion points: Webhook payloads processed by agents as described in resources/coordination.md.
  • Boundary markers: Includes implementation details for Bearer token authentication to secure webhook endpoints.
  • Capability inventory: Full access to the Tigris SDK for object storage, bucket management, and IAM operations.
  • Sanitization: Examples demonstrate standard JSON parsing of external data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 06:26 PM