gpc-android-cli-interop

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a routing utility between different toolchains and does not contain malicious instructions or attempts to bypass security filters.- [COMMAND_EXECUTION]: The skill demonstrates the use of android and gpc CLI tools for standard development tasks such as building, scanning, and publishing applications. All execution patterns are consistent with the stated purpose.- [EXTERNAL_DOWNLOADS]: Links provided in the documentation point to GitHub Pages (yasserstudio.github.io) and official Google development blogs. These references are used for documentation and do not involve untrusted code execution.- [DATA_EXPOSURE]: The skill handles application artifacts like AAB and APK files for the purpose of Google Play Store deployment. No sensitive environment variables or private keys are accessed or exfiltrated.- [PROMPT_INJECTION]: The skill uses a gpc changelog generate --format prompt feature which identifies an indirect prompt injection surface where external changelog data is formatted for the agent. However, this is a standard operational feature and does not constitute a direct threat in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 05:30 AM