lca-publish-executor
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the vendor-provided
tiangongCLI (specificallytiangong publish run) to process LCA bundles. This is the primary intended function of the skill and aligns with the author's identity as 'tiangong-lca'. - [DATA_EXPOSURE]: The skill processes artifact bundles and JSON request files from the local filesystem as directed by the user. No evidence of unauthorized file access or data exfiltration to external domains was found.
- [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic code execution patterns (such as eval or remote package installation) are present in the provided scripts.
Audit Metadata