lightning-studios

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the lightning CLI and the lightning-sdk Python library to create, start, stop, and manage cloud studios. This includes running shell commands and Python scripts on remote cloud machines.
  • [EXTERNAL_DOWNLOADS]: The skill manages its own environment by installing or upgrading the lightning-sdk package from the official Python package registry. These downloads are standard for the vendor's provided tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external sources, including cloud API responses and remote command outputs, creating a surface for indirect instructions.
  • Ingestion points: The agent reads command outputs via studio.run and logs using tail from remote studios, as well as metadata from lightning api calls.
  • Boundary markers: The instructions do not define specific delimiters or warnings to help the agent distinguish between data and potential instructions embedded within the logs or API responses.
  • Capability inventory: The agent possesses significant permissions, such as deleting studios (lightning studio delete), stopping compute resources, and transferring files (lightning cp).
  • Sanitization: No explicit logic is provided to sanitize or filter the retrieved log content or API data before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:51 PM
Security Audit — agent-trust-hub — lightning-studios