gplay-vitals
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Google Play quality signals, including crash reports and stack traces. This content is untrusted and could serve as a vector for indirect prompt injection if an attacker-controlled application triggers specific errors or anomalies.
- Ingestion points: Data retrieved via
gplay vitals errors reports,gplay vitals errors issues, andgplay vitals anomalies(SKILL.md). - Boundary markers: Absent; the instructions do not define delimiters or specific "ignore" instructions for the agent when processing the fetched report content.
- Capability inventory: The skill uses the
gplayCLI to read metrics and error details. - Sanitization: No sanitization, filtering, or validation of the retrieved stack traces or report bodies is described in the instructions.
Audit Metadata