lazycat-developer-expert

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as an expert documentation assistant. It uses a "lazy-loading" strategy to read local reference files based on user queries to provide accurate technical guidance.
  • [COMMAND_EXECUTION]: The documentation provides instructions for users to run platform-specific CLI tools (e.g., lzc-cli project build, lzc-cli appstore publish). These are standard developer workflows and are not executed autonomously by the agent.
  • [PRIVILEGE_ESCALATION]: The references/troubleshooting.md file contains advice on using Docker's privileged: true and cap_add settings. This is documented as a necessary configuration for specific low-level applications (like VPNs) and is a standard feature of the container platform being described.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads from its own references/ directory to supplement the main prompt. This ingestion of local static documentation to inform agent responses is an intended design pattern and does not introduce external data risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:44 PM
Security Audit — agent-trust-hub — lazycat-developer-expert