lightning-blog
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Installs the official
lightning-sdkfrom PyPI to provide blog management capabilities. It also suggests installing image processing libraries such ascairosvgorlibrsvg. - [COMMAND_EXECUTION]: Executes system commands including the
lightningCLI,curl,jq,python3, and potentially headless Chrome to manage API requests, process JSON content, and generate site screenshots. - [DATA_EXFILTRATION]: Accesses the vendor-specific credential file at
~/.lightning/credentials.json. These credentials are used to authenticatecurlmultipart requests for image uploads to the officiallightning.aiAPI endpoints. - [INDIRECT_PROMPT_INJECTION]: Features a script,
md2blocks.py, that processes user-supplied Markdown content and converts it into structured EditorJS blocks. - Ingestion points: Reads Markdown input from files or stdin for conversion.
- Boundary markers: None explicitly defined in the script, though the skill instructions emphasize manual review and user confirmation before publication.
- Capability inventory: The skill maintains capabilities for network communication via the CLI and file system access for content management.
- Sanitization: The conversion script uses
html.escapeto sanitize inline text and ensure only a safe subset of HTML is rendered in the blog editor.
Audit Metadata