Agent skill

Play Policy Insights

by arindamxd in arindamxd/camerax-android

Automated auditor designed to verify Android applications against Google Play Policy domains.

Apache-2.0Auto-check passedMobile

Install Play Policy Insights

skills CLI
$ npx skills add arindamxd/camerax-android --skill play-policy-insights -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install arindamxd/camerax-android play-policy-insights --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/arindamxd/camerax-android.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/play-policy-insights .claude/skills/play-policy-insights && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
play-policy-insights
GitHub stars
132
Used in
2 other repos
Token cost
~2.1k tokens
SKILL.md length
916 words
Files
14 (incl. scripts)
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Automated auditor designed to verify Android applications against Google Play Policy domains.

  • Works in 2 steps: Fact gathering and triage → Goal-oriented audit
  • Tasks that involve App store release
  • SKILL.md covers Path Resolution, Critical mandates and The two-phase protocol
  • Runs Python scripts from its folder; calls python3

What it does

Play Policy Insights is an agent skill from arindamxd/camerax-android. Automated auditor designed to verify Android applications against Google Play Policy domains. It cross-references static code analysis with Play Store declarations to generate deterministic compliance reports, identifying undeclared data collection, architectural risks, and missing disclosures across Permissions and APIs Hygiene, User Account and Identity, and Data Safety and Privacy domains.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts (for example `resources/common_mandates.md`, `resources/compliance_report_template.md` and `resources/critic.md`).

It sits in Mobile, covering App store release and Subagents. It works with Android. The repository describes itself as: A Play Store camera app showing Jetpack CameraX APIs in Kotlin — install it, use it, copy the patterns. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve App store release
  • Tasks that involve Subagents

Example prompts

  • “/play-policy-insights”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Fact gathering and triage
  2. Goal-oriented audit

What it can do on your machine

Read from SKILL.md and the folder at commit 7c36352. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Play Policy Insights loads about 2.1k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 916 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from arindamxd/camerax-android at commit 7c36352, republished under its Apache-2.0 licence (© arindamxd). 916 words, ~2,131 tokens.

Download SKILL.mdSave it as .claude/skills/play-policy-insights/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
play-policy-insights
description
Automated auditor designed to verify Android applications against Google Play Policy domains. It cross-references static code analysis with Play Store declarations to generate deterministic compliance reports, identifying undeclared data collection, architectural risks, and missing disclosures across Permissions and APIs Hygiene, User Account and Identity, and Data Safety and Privacy domains.
license
Complete terms in LICENSE.txt
metadata.author
Google LLC
metadata.last-updated
2026-07-13
metadata.keywords
account deletion, accessibility api, all files access, audio recording, audit, compliance, contacts access, data disclosure, data safety, data safety label…

Play Policy Insights: data safety, login credentials, and restricted permissions

You must audit Android apps for three specific policy domains. You must check data safety, demo login credentials, and restricted permissions.

Path Resolution

  • repo_root: Absolute path to the directory containing this SKILL.md.
  • app_dir:: Absolute path to the directory containing app's code.
  • temp_dir: Absolute path to the scratch directory at the workspace root. It is located at .scratch/play_policy_insights_<uuid>. Containment Mandate: You must confine all file system writes, intermediate artifacts, and logs strictly to this directory. This ensures the skill remains portable and safe across diverse execution environments, including local harnesses and CI/CD pipelines, by avoiding reliance on system-level temporary paths or user home directories.

Critical mandates

  • Execution Mode Awareness Before starting Phase 2, evaluate if your execution environment provides a tool to spawn or delegate tasks to general-purpose sub-agents (e.g., tools often named invoke_agent, delegate_task, or spawn_worker, using generic agent profiles like 'generalist' or 'coding_agent').

  • If YES, you MUST use Mode A (Delegation).

  • If NO, use Mode B (Sequential Self-Execution). You must read the prompt files intended for the subagents, follow their instructions, and write the expected output files to disk.

  • Sub-agents orchestration:

    • If you use "Mode A (Delegation)", wait for "SUCCESS" confirmation from sub-agents to know when they are done.

    • Idempotency & Timeout Safeguard: If a sub-agent fails or times out, you MUST verify the presence and integrity of its target output file (e.g., <temp_dir>/worker_<goal_name>.json) before retrying. If the file exists and contains valid JSON, treat the execution as SUCCESS and proceed. Otherwise, retry up to three times.

  • Fail-fast mandate: The automated audit in Phase 1 is the source of truth. If orchestrator.py fails, you must stop immediately with an explanation of failure. Do not use manual auditing as a fallback.

The two-phase protocol

Phase 1: Fact gathering and triage
  1. Initialize and triage:
    • Run python3 <repo_root>/scripts/orchestrator.py init <app_dir>.
    • This will create the scratch environment, perform static analysis, map the codebase, identify audit goals, and produce prompts for subagents for each audit goal and prompts for designated critic and aggregator subagents.
    • You must wait (up to 5 minutes) for the script to finish.
  2. Capture environment: Note values of the temp_dir, and activated_goals from the JSON output. You will need them in Phase 2.
  3. Evaluate goals: If activated_goals is empty, skip to step 3 of Phase 2 (Aggregation). Otherwise, proceed to step 1 of Phase 2 (Detailed analysis).
Phase 2: Goal-oriented audit

Determine your execution capabilities and proceed with either Mode A OR Mode B.

Show full SKILL.md (501 more words)Show less
Mode A: Orchestrator WITH Delegation Capabilities (Parallel)
  1. Detailed analysis: For each goal in activated_goals (e.g., permissions_and_apis, data_safety_part_1, data_safety_part_2), delegate to a sub-agent. Concurrency Limit: You must not spawn more than 3 sub-agents simultaneously. Spawn the first batch of up to 3, wait for their completions, and then spawn the next batch. Repeat until all goals are complete. Pass the prompt: "Read your instructions from <temp_dir>/prompt_worker_<goal_name>.md and execute. MANDATORY: You must use your file-writing capabilities to save your final JSON findings directly to the file system at <temp_dir>/worker_<goal_name>.json. You are strictly forbidden from outputting the JSON in your chat response. To minimize context usage, your final response must be exactly 'SUCCESS' and nothing else." Validate: Confirm every <temp_dir>/worker_<goal_name>.json exists and contains valid JSON. If a sub-agent fails or times out, but the valid JSON output file is already present on disk, do NOT retry; proceed normally. Only retry the corresponding worker (up to three times) if the file is missing or invalid.
  2. Aggregate Findings: Execute the python aggregation command: python3 <repo_root>/scripts/orchestrator.py aggregate <temp_dir>. This produces aggregated_findings.json and returns a JSON object containing critic_chunks representing the number of chunks to verify (e.g., {"temp_dir": "...", "critic_chunks": 2}).
  3. Parallel Critic review: For each chunk index i from 1 to critic_chunks, delegate to a sub-agent. Concurrency Limit: You must not spawn more than 3 critic sub-agents simultaneously. Batch them in groups of 3 as above. Pass the prompt: "Read your instructions from <temp_dir>/prompt_critic_<i>.md and execute. MANDATORY: You must use your file-writing capabilities to save your final JSON findings directly to the file system at <temp_dir>/critic_output_<i>.json. You are strictly forbidden from outputting the JSON in your chat response. To minimize context usage, your final response must be exactly 'SUCCESS' and nothing else." Validate: Confirm each <temp_dir>/critic_output_<i>.json exists and contains valid JSON before proceeding. If it failed or timed out, but the valid JSON file is present, proceed normally. Otherwise, retry that specific critic chunk.
  4. Proceed to Finalization (Step 4 below)
Mode B: Orchestrator WITHOUT Delegation Capabilities (Sequential)
  1. Detailed Analysis: For each goal in activated_goals, sequentially:
    • Read the contents of <temp_dir>/prompt_worker_<goal_name>.md.
    • Execute the instructions contained within that file yourself.
    • CRITICAL: You MUST format your findings exactly as requested in the prompt and save them to <temp_dir>/worker_<goal_name>.json. Do not summarize findings in your thoughts or chat; move to the next task.
    • Validate: Confirm <temp_dir>/worker_<goal_name>.json exists before moving to the next goal.
  2. Aggregate Findings: Execute the python aggregation command: python3 <repo_root>/scripts/orchestrator.py --aggregate <temp_dir>. This produces aggregated_findings.json and returns a JSON object containing critic_chunks representing the number of chunks to verify.
  3. Sequential Critic review: For each chunk index i from 1 to critic_chunks, sequentially:
    • Read the contents of <temp_dir>/prompt_critic_<i>.md.
    • Execute the steps yourself and save your findings to <temp_dir>/critic_output_<i>.json.
    • Validate: Confirm <temp_dir>/critic_output_<i>.json exists before moving to the next chunk.
  4. Proceed to Finalization (Step 4 below)
Finalization (Both Modes)
  1. Present findings: Run python3 <repo_root>/scripts/generate_report.py <temp_dir>. It will produce <temp_dir>/compliance_report.md. Present this output file to user.
  2. STOP: The audit is complete. Await further instructions.

© arindamxd, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts) in .agents/skills/play-policy-insights of arindamxd/camerax-android.

  • SKILL.md
  • resources/common_mandates.md
  • resources/compliance_report_template.md
  • resources/critic.md
  • resources/goal_data_safety.md
  • resources/goal_permissions_and_apis.md
  • resources/goal_user_account.md
  • resources/policies.json
  • resources/scanner_config.json
  • scripts/generate_report.py
  • scripts/orchestrator.py
  • scripts/play_store_scraper.py
  • scripts/scanner.py
  • scripts/template_engine.py

Open the folder on GitHubat commit 7c36352

Used in 2 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in arindamxd/camerax-android, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Play Policy Insights next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Play Policy Insights compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Play Policy Insights this skillarindamxd/camerax-android1322 repos~2.1kAutomated safety check: PassApache-2.0
Screenshotsshortcuts/locationjoystick104—~3.1kAutomated safety check: PassMIT
Reply Reviewstimusus/Shuttle2229—~1kAutomated safety check: PassApache-2.0
Pp Google Playmvanhorn/printing-press-library2.1k—~3.4kAutomated safety check: NotesApache-2.0
Cometchat Android V6 Productioncometchat/cometchat-skills131—~1.7kAutomated safety check: PassMIT
Gplay Metadata Synchanamizuki/solopreneur152—~1.4kAutomated safety check: PassMIT

Similar skills

  • Screenshots

    shortcuts/locationjoystick

    Refresh all wiki/Play Store gallery screenshots from a connected Android device.

    104 GitHub stars~3.1k tokensUpdated yesterday
    MobileAuto-check passed
  • Reply Reviews

    timusus/Shuttle2

    Weekly Play Store review flow for S2: fetch new reviews, draft replies, get owner approval, then post.

    229 GitHub stars~1k tokensUpdated today
    MobileAuto-check passed
  • Pp Google Play

    mvanhorn/printing-press-library

    Every public Google Play surface in one Go binary Trigger phrases: top grossing games on google play, google play app details for, track this app's rank over time, what changed on this play store…

    2.1k GitHub stars~3.4k tokensUpdated today
    MobileAuto-check: notes
  • Cometchat Android V6 Production

    cometchat/cometchat-skills

    Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning…

    131 GitHub stars~1.7k tokensUpdated 4 days ago
    MobileAuto-check passed
  • Gplay Metadata Sync

    hanamizuki/solopreneur

    Metadata and localization sync (including Fastlane format) for Google Play Store listings.

    152 GitHub stars~1.4k tokensUpdated 13 days ago
    MobileAuto-check passed
  • Gplay Migrate Fastlane

    hanamizuki/solopreneur

    Migration from Fastlane supply to gplay CLI using the gplay migrate fastlane command.

    152 GitHub stars~1.2k tokensUpdated 13 days ago
    MobileAuto-check passed

More from arindamxd/camerax-android

All 21 skills in this repo
  • Styles

    arindamxd/camerax-android

    A skill your agent uses to integrate the Jetpack Compose Styles API into an Android project.

    132 GitHub starsUsed in 4 repos~2.3k tokens
    Auto-check passed
  • Verified Email

    arindamxd/camerax-android

    Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API.

    132 GitHub starsUsed in 4 repos~4.7k tokens
    Auto-check passed
  • Edge To Edge

    arindamxd/camerax-android

    A skill your agent uses to migrate your Jetpack Compose app to add adaptive edge-to-edge support and troubleshoot common issues.

    132 GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Camerax

    arindamxd/camerax-android

    Provide technical guidance for Android camera development with CameraX.

    132 GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check passed
  • Leanback To Compose Tv Migration

    arindamxd/camerax-android

    Provides instructions and architectural patterns for migrating Android TV applications from legacy Leanback UI Toolkit, Android Views, or Support Fragments to Jetpack Compose for TV (androidx.tv).

    132 GitHub starsUsed in 2 repos~8.7k tokens
    Auto-check passed
  • Migrate XML Views To Jetpack Compose

    arindamxd/camerax-android

    Provides a structured workflow for migrating an Android XML View to Jetpack Compose.

    132 GitHub starsUsed in 5 repos~1.4k tokens
    Auto-check passed

Works with

Categories

Questions about Play Policy Insights

What does Play Policy Insights do?

Automated auditor designed to verify Android applications against Google Play Policy domains. Play Policy Insights is an agent skill from arindamxd/camerax-android. Automated auditor designed to verify Android applications against Google Play Policy domains.

When should I use Play Policy Insights?

Play Policy Insights fits situations like: tasks that involve App store release; tasks that involve Subagents.

How do I install Play Policy Insights in Claude Code?

Run `npx skills add arindamxd/camerax-android --skill play-policy-insights -a claude-code`. Or copy the skill folder (.agents/skills/play-policy-insights in arindamxd/camerax-android) into .claude/skills/play-policy-insights in your project. Claude Code loads it when a task matches its description.

How do I install Play Policy Insights in Codex?

Run `npx skills add arindamxd/camerax-android --skill play-policy-insights -a codex`. Or copy the skill folder (.agents/skills/play-policy-insights in arindamxd/camerax-android) into .agents/skills/play-policy-insights in your project. Codex loads it when a task matches its description.

Can I use Play Policy Insights in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arindamxd/camerax-android --skill play-policy-insights -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/play-policy-insights, .gemini/skills/play-policy-insights, .github/skills/play-policy-insights and .opencode/skills/play-policy-insights in your project.

What does Play Policy Insights need to run?

Going by SKILL.md and its folder, Play Policy Insights needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Play Policy Insights access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Play Policy Insights safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Play Policy Insights use?

Play Policy Insights is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Play Policy Insights use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Play Policy Insights?

Skills that share tags, products or a category with Play Policy Insights: Screenshots (shortcuts/locationjoystick, 104 stars), Reply Reviews (timusus/Shuttle2, 229 stars), Pp Google Play (mvanhorn/printing-press-library, 2.1k stars) and Cometchat Android V6 Production (cometchat/cometchat-skills, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Play Policy Insights?

arindamxd (a GitHub user) maintains it in arindamxd/camerax-android, which has 132 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 2, 2026.

Source: arindamxd/camerax-android on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.