lightning-artifacts

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the lightning-sdk package using standard package managers such as pip or uv. This is the official SDK provided by the vendor lightning-ai and is required for the skill's primary functionality.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from API responses and file system listings which constitutes a potential attack surface. However, it does not perform high-risk autonomous actions based on this content and uses structured parsing for safety.\n
  • Ingestion points: SKILL.md (via shell command outputs from lightning ls and lightning api)\n
  • Boundary markers: Absent\n
  • Capability inventory: File upload (lightning cp), file deletion (lightning rm), and artifact registration (lightning api)\n
  • Sanitization: The skill employs jq for structured data parsing and uses shell variable quoting in its utility functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:51 PM
Security Audit — agent-trust-hub — lightning-artifacts