lightning-jobs

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to install or upgrade the lightning-sdk Python package from standard registries using pip or uv. This package is a legitimate library provided by the vendor to interface with Lightning AI services.
  • [COMMAND_EXECUTION]: The skill performs shell operations using the lightning CLI, including authentication (lightning login) and job management commands. These commands are used to initiate and control workloads on the Lightning AI platform.
  • [DYNAMIC_EXECUTION]: The skill is designed to run user-provided commands and scripts on remote cloud machines (e.g., lightning job run --command "..."). This dynamic execution is the core intended purpose of the skill for handling batch processing and training tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external sources, specifically logs and artifacts generated by remote jobs. This creates an attack surface where malicious instructions embedded in job outputs could attempt to influence the agent's logic during result analysis.
  • Ingestion points: Accessing logs via lightning job logs and downloading files via lightning cp or job.download_artifacts().
  • Boundary markers: No specific boundary markers or "ignore" instructions are defined for the parsing of log content or artifact data.
  • Capability inventory: The skill allows for network communication with lightning.ai and command execution on cloud infrastructure.
  • Sanitization: There is no evidence of specific sanitization or filtering of external job output before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:51 PM
Security Audit — agent-trust-hub — lightning-jobs