lca-publish-executor

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The Node.js script 'scripts/run-lca-publish-executor.mjs' is designed to invoke the vendor's CLI tool 'tiangong publish run' with arguments forwarded from the agent. This execution is part of the intended functionality for artifact publishing within the vendor's ecosystem.- [EXTERNAL_DOWNLOADS]: The skill uses internal relative imports for its launcher logic and references official documentation. It does not perform any downloads from untrusted third-party sources or unknown domains.- [SAFE]: Analysis of the instruction files and scripts found no evidence of prompt injection, data exfiltration, hardcoded credentials, or obfuscated code. The use of a JSON schema for request validation follows security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 06:57 AM
Security Audit — agent-trust-hub — lca-publish-executor