gplay-customapps

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructions for a developer CLI tool that integrates with the official Google Play Developer API. It promotes safety best practices including a mandatory --confirm flag for irreversible actions.
  • [COMMAND_EXECUTION]: Describes usage of the gplay CLI. The skill outlines controlled execution paths with specific exit codes for failures and safety violations.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves an ingestion surface where external files are passed to a CLI tool. * Ingestion points: Artifact paths for Android App Bundles (AAB) or APKs. * Boundary markers: Not applicable to binary artifact content. * Capability inventory: Subprocess execution of the gplay CLI. * Sanitization: None specified for the binary input files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:58 PM
Security Audit — agent-trust-hub — gplay-customapps