lca-publish-executor

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the vendor-provided tiangong CLI (specifically tiangong publish run) to process LCA bundles. This is the primary intended function of the skill and aligns with the author's identity as 'tiangong-lca'.
  • [DATA_EXPOSURE]: The skill processes artifact bundles and JSON request files from the local filesystem as directed by the user. No evidence of unauthorized file access or data exfiltration to external domains was found.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic code execution patterns (such as eval or remote package installation) are present in the provided scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:16 AM