lightning-blog

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the official lightning-sdk from PyPI to provide blog management capabilities. It also suggests installing image processing libraries such as cairosvg or librsvg.
  • [COMMAND_EXECUTION]: Executes system commands including the lightning CLI, curl, jq, python3, and potentially headless Chrome to manage API requests, process JSON content, and generate site screenshots.
  • [DATA_EXFILTRATION]: Accesses the vendor-specific credential file at ~/.lightning/credentials.json. These credentials are used to authenticate curl multipart requests for image uploads to the official lightning.ai API endpoints.
  • [INDIRECT_PROMPT_INJECTION]: Features a script, md2blocks.py, that processes user-supplied Markdown content and converts it into structured EditorJS blocks.
  • Ingestion points: Reads Markdown input from files or stdin for conversion.
  • Boundary markers: None explicitly defined in the script, though the skill instructions emphasize manual review and user confirmation before publication.
  • Capability inventory: The skill maintains capabilities for network communication via the CLI and file system access for content management.
  • Sanitization: The conversion script uses html.escape to sanitize inline text and ensure only a safe subset of HTML is rendered in the blog editor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:31 PM
Security Audit — agent-trust-hub — lightning-blog