gplay-vitals

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Google Play quality signals, including crash reports and stack traces. This content is untrusted and could serve as a vector for indirect prompt injection if an attacker-controlled application triggers specific errors or anomalies.
  • Ingestion points: Data retrieved via gplay vitals errors reports, gplay vitals errors issues, and gplay vitals anomalies (SKILL.md).
  • Boundary markers: Absent; the instructions do not define delimiters or specific "ignore" instructions for the agent when processing the fetched report content.
  • Capability inventory: The skill uses the gplay CLI to read metrics and error details.
  • Sanitization: No sanitization, filtering, or validation of the retrieved stack traces or report bodies is described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:58 PM
Security Audit — agent-trust-hub — gplay-vitals