lightning-artifacts
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the lightning-sdk package using standard package managers such as pip or uv. This is the official SDK provided by the vendor lightning-ai and is required for the skill's primary functionality.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from API responses and file system listings which constitutes a potential attack surface. However, it does not perform high-risk autonomous actions based on this content and uses structured parsing for safety.\n
- Ingestion points: SKILL.md (via shell command outputs from lightning ls and lightning api)\n
- Boundary markers: Absent\n
- Capability inventory: File upload (lightning cp), file deletion (lightning rm), and artifact registration (lightning api)\n
- Sanitization: The skill employs jq for structured data parsing and uses shell variable quoting in its utility functions.
Audit Metadata