lighter
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using
subprocess.runto manage its own environment. - Evidence: The
_install_depsfunction inclient.pyexecutessubprocess.run([sys.executable, "-m", "pip", "install", ...])to install required dependencies at runtime. - [EXTERNAL_DOWNLOADS]: The skill fetches and installs external software packages from public registries during execution.
- Evidence:
client.pyusespipto install thelighter-sdkand other libraries listed in a localrequirements.lockfile into a vendor directory. - [DYNAMIC_EXECUTION]: The skill dynamically modifies the execution environment by altering the Python search path and importing code at runtime.
- Evidence: The functions
ensure_lighter_sdkand_prepend_vendorinclient.pyadd a custom vendor directory tosys.pathand subsequently import the dynamically installedlighterSDK. - [INDIRECT_PROMPT_INJECTION]: The skill possesses high-privilege capabilities and ingests untrusted market data from external API endpoints, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Tools such as
lighter_get_markets,lighter_get_orderbook, andlighter_get_recent_trades(intools.py) fetch data from the Lighter DEX REST API. - Boundary markers: Absent; the skill does not use specific delimiters or instructions to notify the agent to ignore embedded instructions in the tool output.
- Capability inventory: High-privilege tools include
lighter_create_order,lighter_withdraw, andlighter_transfer_funds(intools.py). - Sanitization: Absent; responses from the external API are returned directly to the agent as JSON strings without sanitization.
Audit Metadata