lightning-studios
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
lightningCLI and thelightning-sdkPython library to create, start, stop, and manage cloud studios. This includes running shell commands and Python scripts on remote cloud machines. - [EXTERNAL_DOWNLOADS]: The skill manages its own environment by installing or upgrading the
lightning-sdkpackage from the official Python package registry. These downloads are standard for the vendor's provided tools. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external sources, including cloud API responses and remote command outputs, creating a surface for indirect instructions.
- Ingestion points: The agent reads command outputs via
studio.runand logs usingtailfrom remote studios, as well as metadata fromlightning apicalls. - Boundary markers: The instructions do not define specific delimiters or warnings to help the agent distinguish between data and potential instructions embedded within the logs or API responses.
- Capability inventory: The agent possesses significant permissions, such as deleting studios (
lightning studio delete), stopping compute resources, and transferring files (lightning cp). - Sanitization: No explicit logic is provided to sanitize or filter the retrieved log content or API data before the agent processes it.
Audit Metadata