gps-reviews

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with the Google Play Store through a CLI tool to manage reviews. All operations are within the expected scope of the skill's description.
  • [COMMAND_EXECUTION]: The skill executes the gps command-line utility. These commands are used for listing, getting, and replying to reviews, which is consistent with the primary purpose of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of store reviews. While this presents an attack surface for indirect prompt injection, the skill mitigates this by explicitly requiring human-in-the-loop confirmation before any reply is posted, preventing the agent from autonomously acting on instructions found within reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:34 PM
Security Audit — agent-trust-hub — gps-reviews