lazycat-lpk-builder

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the use of lzc-cli for common developer tasks such as building application packages, installing services, and interacting with containerized environments. These operations are limited to the user's development environment and the platform's CLI tools.
  • [REMOTE_CODE_EXECUTION]: The documentation describes platform-native features like setup_script and buildscript, which allow for shell command execution during application initialization or build time. These are standard extensibility points for the LPK format used to configure software environments.
  • [EXTERNAL_DOWNLOADS]: Mentions pushing and pulling container images from the platform's official registries, including registry.lazycat.cloud and developer-specific subdomains on heiyu.space. These are recognized as legitimate infrastructure for the Lazycat platform.
  • [PROMPT_INJECTION]: The skill acts as an assistant for processing user-defined configurations. It includes a specific 'Guardrails' section designed to prevent the agent from generating unsafe configurations, such as infinite build loops or invalid service communication patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 10:42 AM