lazycat-lpk-builder
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of
lzc-clifor common developer tasks such as building application packages, installing services, and interacting with containerized environments. These operations are limited to the user's development environment and the platform's CLI tools. - [REMOTE_CODE_EXECUTION]: The documentation describes platform-native features like
setup_scriptandbuildscript, which allow for shell command execution during application initialization or build time. These are standard extensibility points for the LPK format used to configure software environments. - [EXTERNAL_DOWNLOADS]: Mentions pushing and pulling container images from the platform's official registries, including
registry.lazycat.cloudand developer-specific subdomains onheiyu.space. These are recognized as legitimate infrastructure for the Lazycat platform. - [PROMPT_INJECTION]: The skill acts as an assistant for processing user-defined configurations. It includes a specific 'Guardrails' section designed to prevent the agent from generating unsafe configurations, such as infinite build loops or invalid service communication patterns.
Audit Metadata