mine-play-reviews
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the 'google-play-scraper' Node.js package from the public registry to perform data collection.
- [COMMAND_EXECUTION]: A Node.js command-line snippet is provided to execute scraping logic and output review data.
- [PROMPT_INJECTION]: The skill processes untrusted data from external app reviews, presenting a surface for indirect prompt injection. * Ingestion points: Reviews are pulled from the Play Store via an external library (SKILL.md). * Boundary markers: The skill lacks specific instructions for delimiting external content. * Capability inventory: The agent processes data and writes findings to the filesystem (SKILL.md). * Sanitization: No sanitization of the review content is mentioned before processing.
Audit Metadata