gps-internal-sharing
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
gpsCLI tool to perform uploads of.aaband.apkfiles to Google Play Store services. - [INDIRECT_PROMPT_INJECTION]: The skill defines a process for handling external data (application builds and API responses) which is a standard vector for indirect prompt injection.
- Ingestion points: Reads
./app-release.aaband./app-release.apkbuild artifacts from the local environment. - Boundary markers: No specific delimiters or safety instructions are provided for handling the file content or the API response.
- Capability inventory: The skill is capable of executing shell commands through the
gpsutility. - Sanitization: The API response (download URL) is returned to the user without additional validation or sanitization steps.
Audit Metadata