lightning-deployments

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the lightning-sdk Python package from standard package registries. This is the official SDK provided by the vendor.
  • [COMMAND_EXECUTION]: The skill utilizes the lightning command-line interface to manage cloud resources, including creating container deployments, serving AI models, and retrieving logs.
  • [CREDENTIALS_UNSAFE]: The skill manages authentication using the LIGHTNING_API_KEY environment variable. It provides instructions for users to set these credentials but does not include hardcoded secrets or exfiltration logic.
  • [DYNAMIC_EXECUTION]: The skill includes a Python code snippet that monkey-patches the lightning_sdk at runtime to add support for private container image secrets, addressing a temporary limitation in the official SDK.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses JSON data from the Lightning AI API (e.g., membership and deployment status) to resolve configuration details, which constitutes a data ingestion surface.
  • Ingestion points: Reads output from lightning api /v1/memberships and lightning deployment inspect in SKILL.md.
  • Boundary markers: None explicitly defined for API parsing, though standard JSON parsing is expected.
  • Capability inventory: Includes subprocess calls via lightning CLI, file-write capabilities through config sets, and network operations via lightning api and curl.
  • Sanitization: Uses jq for filtering and extracting specific fields from structured JSON data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:51 PM
Security Audit — agent-trust-hub — lightning-deployments