gplay-apps

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFENO_CODECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown documentation and usage examples. No executable scripts, binaries, or configuration files that could run code are included.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands using the gplay CLI. These commands are consistent with the skill's stated purpose of managing a local package registry and updating app details.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes tools that ingest data from external sources, specifically the Google Play API (app titles, contact information), which could potentially contain malicious content intended for the agent. 1. Ingestion points: Data retrieved via gplay apps view and gplay apps details view as described in SKILL.md. 2. Boundary markers: The instructions do not specify any delimiters or safety markers for processing the tool output. 3. Capability inventory: The agent uses shell commands to interact with the gplay CLI, which performs network requests. 4. Sanitization: There is no evidence of output sanitization or validation within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:59 PM
Security Audit — agent-trust-hub — gplay-apps