lca-publish-executor
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The Node.js script 'scripts/run-lca-publish-executor.mjs' is designed to invoke the vendor's CLI tool 'tiangong publish run' with arguments forwarded from the agent. This execution is part of the intended functionality for artifact publishing within the vendor's ecosystem.- [EXTERNAL_DOWNLOADS]: The skill uses internal relative imports for its launcher logic and references official documentation. It does not perform any downloads from untrusted third-party sources or unknown domains.- [SAFE]: Analysis of the instruction files and scripts found no evidence of prompt injection, data exfiltration, hardcoded credentials, or obfuscated code. The use of a JSON schema for request validation follows security best practices.
Audit Metadata