lightning-deployments
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
lightning-sdkPython package from standard package registries. This is the official SDK provided by the vendor. - [COMMAND_EXECUTION]: The skill utilizes the
lightningcommand-line interface to manage cloud resources, including creating container deployments, serving AI models, and retrieving logs. - [CREDENTIALS_UNSAFE]: The skill manages authentication using the
LIGHTNING_API_KEYenvironment variable. It provides instructions for users to set these credentials but does not include hardcoded secrets or exfiltration logic. - [DYNAMIC_EXECUTION]: The skill includes a Python code snippet that monkey-patches the
lightning_sdkat runtime to add support for private container image secrets, addressing a temporary limitation in the official SDK. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses JSON data from the Lightning AI API (e.g., membership and deployment status) to resolve configuration details, which constitutes a data ingestion surface.
- Ingestion points: Reads output from
lightning api /v1/membershipsandlightning deployment inspectin SKILL.md. - Boundary markers: None explicitly defined for API parsing, though standard JSON parsing is expected.
- Capability inventory: Includes subprocess calls via
lightningCLI, file-write capabilities through config sets, and network operations vialightning apiandcurl. - Sanitization: Uses
jqfor filtering and extracting specific fields from structured JSON data.
Audit Metadata