android-ci-cd-release-playstore
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to automate Android CI/CD workflows, which inherently involves the agent reading and acting upon external repository data.
- Ingestion points: The agent is instructed to process repository-specific CI configurations, version metadata flow, and packaging outputs in
SKILL.mdandreferences/scenarios.md. - Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings for the agent when it is parsing project files or script outputs.
- Capability inventory: The skill utilizes script execution capabilities (referencing
python3scripts for validation and release tasks) which could be influenced if the processed data contains malicious instructions. - Sanitization: No sanitization, validation, or integrity checking mechanisms for the external project content are described in the provided workflow or guardrails.
Audit Metadata