lazycat-developer-expert

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides extensive documentation for configuration fields such as buildscript and setup_script, which are designed to facilitate shell command execution during the application build and deployment phases on the Lazycat platform.
  • [COMMAND_EXECUTION]: Documentation within the troubleshooting.md file explains that the setup_script feature executes with root privileges to allow developers to perform necessary system-level initializations and permission adjustments.
  • [REMOTE_CODE_EXECUTION]: The skill details the application.injects capability, which allows for the injection of JavaScript into web applications, including support for scripts retrieved from remote HTTP/HTTPS URLs as a documented platform feature.
  • [EXTERNAL_DOWNLOADS]: The skill references the acquisition of official SDKs and Docker images from well-known or platform-specific registries, including Gitee, the official Lazycat Docker registry, and standard NPM/PyPI mirrors.
  • [CREDENTIALS_UNSAFE]: The documentation includes templates and implementation guidance for handling authentication secrets and API tokens, recommending the use of environmental variables and platform-native CLI tools for secure management.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 12:26 PM