lazycat-developer-expert
Pass
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive documentation for configuration fields such as
buildscriptandsetup_script, which are designed to facilitate shell command execution during the application build and deployment phases on the Lazycat platform. - [COMMAND_EXECUTION]: Documentation within the
troubleshooting.mdfile explains that thesetup_scriptfeature executes with root privileges to allow developers to perform necessary system-level initializations and permission adjustments. - [REMOTE_CODE_EXECUTION]: The skill details the
application.injectscapability, which allows for the injection of JavaScript into web applications, including support for scripts retrieved from remote HTTP/HTTPS URLs as a documented platform feature. - [EXTERNAL_DOWNLOADS]: The skill references the acquisition of official SDKs and Docker images from well-known or platform-specific registries, including Gitee, the official Lazycat Docker registry, and standard NPM/PyPI mirrors.
- [CREDENTIALS_UNSAFE]: The documentation includes templates and implementation guidance for handling authentication secrets and API tokens, recommending the use of environmental variables and platform-native CLI tools for secure management.
Audit Metadata