gps-internal-sharing

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the gps CLI tool to perform uploads of .aab and .apk files to Google Play Store services.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for handling external data (application builds and API responses) which is a standard vector for indirect prompt injection.
  • Ingestion points: Reads ./app-release.aab and ./app-release.apk build artifacts from the local environment.
  • Boundary markers: No specific delimiters or safety instructions are provided for handling the file content or the API response.
  • Capability inventory: The skill is capable of executing shell commands through the gps utility.
  • Sanitization: The API response (download URL) is returned to the user without additional validation or sanitization steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 02:45 PM
Security Audit — agent-trust-hub — gps-internal-sharing