lighter

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using subprocess.run to manage its own environment.
  • Evidence: The _install_deps function in client.py executes subprocess.run([sys.executable, "-m", "pip", "install", ...]) to install required dependencies at runtime.
  • [EXTERNAL_DOWNLOADS]: The skill fetches and installs external software packages from public registries during execution.
  • Evidence: client.py uses pip to install the lighter-sdk and other libraries listed in a local requirements.lock file into a vendor directory.
  • [DYNAMIC_EXECUTION]: The skill dynamically modifies the execution environment by altering the Python search path and importing code at runtime.
  • Evidence: The functions ensure_lighter_sdk and _prepend_vendor in client.py add a custom vendor directory to sys.path and subsequently import the dynamically installed lighter SDK.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses high-privilege capabilities and ingests untrusted market data from external API endpoints, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Tools such as lighter_get_markets, lighter_get_orderbook, and lighter_get_recent_trades (in tools.py) fetch data from the Lighter DEX REST API.
  • Boundary markers: Absent; the skill does not use specific delimiters or instructions to notify the agent to ignore embedded instructions in the tool output.
  • Capability inventory: High-privilege tools include lighter_create_order, lighter_withdraw, and lighter_transfer_funds (in tools.py).
  • Sanitization: Absent; responses from the external API are returned directly to the agent as JSON strings without sanitization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 09:10 AM
Security Audit — agent-trust-hub — lighter