play-developer-console
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose broadly matches its capabilities and uses official Google ADC-style auth, but it depends on a local unpublished `play` CLI and repo-defined Bun scripts that are not independently verifiable. Because that local tool likely receives Play/Google credentials and can perform production-affecting release actions, the overall security risk is high even without evidence of explicit exfiltration or confirmed malware.
Confidence: 87%Severity: 81%
Audit Metadata