mine-play-reviews

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the 'google-play-scraper' Node.js package from the public registry to perform data collection.
  • [COMMAND_EXECUTION]: A Node.js command-line snippet is provided to execute scraping logic and output review data.
  • [PROMPT_INJECTION]: The skill processes untrusted data from external app reviews, presenting a surface for indirect prompt injection. * Ingestion points: Reviews are pulled from the Play Store via an external library (SKILL.md). * Boundary markers: The skill lacks specific instructions for delimiting external content. * Capability inventory: The agent processes data and writes findings to the filesystem (SKILL.md). * Sanitization: No sanitization of the review content is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:18 PM
Security Audit — agent-trust-hub — mine-play-reviews