gpd-cli

Pass

Audited by Gen Agent Trust Hub on Feb 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates interaction with the Google Play Store by executing the gpd command-line utility for administrative tasks like publishing and rollout management.
  • [PROMPT_INJECTION]: The skill retrieves untrusted data from the Play Store via the gpd reviews list command, which creates an indirect prompt injection surface. 1. Ingestion points: User-submitted reviews retrieved through the gpd reviews list command. 2. Boundary markers: None specified in the skill body. 3. Capability inventory: Extensive administrative control over the Google Play Console through the gpd tool, including release and monetization management. 4. Sanitization: No sanitization or validation of the fetched review text is mentioned.
  • [NO_CODE]: The skill does not bundle any scripts, binaries, or executable code, relying instead on the pre-installation of the external gpd CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 24, 2026, 05:15 AM