tigris-object-operations

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions in SKILL.md direct the agent to install the official @tigrisdata/cli package globally via npm. This is a verified vendor-owned resource for Tigris Data.
  • [COMMAND_EXECUTION]: The skill utilizes command-line checks such as tigris help to verify environment readiness and executes installation commands to ensure required vendor tools are available.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it retrieves content from external storage via the get operation in SKILL.md. This constitutes an ingestion point for untrusted data; however, the risk is managed by standard agent safety protocols as no safety overrides are present.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 10:17 AM