gps-cli

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a documentation file for the gps CLI tool. No malicious code, obfuscation, or unauthorized data exfiltration attempts were found.
  • [PROMPT_INJECTION]: The skill provides an interface for reading user-generated data from the Google Play Store, which acts as a potential indirect prompt injection surface.
  • Ingestion points: gps reviews list and gps listings list in SKILL.md.
  • Boundary markers: None present in the provided instructions.
  • Capability inventory: gps deploy (app release management) and gps call (arbitrary API execution).
  • Sanitization: The skill does not describe any sanitization of the retrieved store data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:34 PM
Security Audit — agent-trust-hub — gps-cli