GPC Preflight Scanner
When to use
Use this skill when the task involves:
- Scanning an AAB or APK file before uploading to Google Play
- Checking target SDK version compliance
- Auditing permissions against Google Play policies
- Verifying 64-bit native library support
- Scanning source code for hardcoded secrets or credentials
- Detecting non-Play billing SDKs
- Checking store listing metadata compliance
- CI/CD quality gates based on policy compliance
Quick reference
# Full scan (AAB or APK)
gpc preflight app.aab
gpc preflight app.apk
# With metadata and source scanning
gpc preflight app.aab --metadata fastlane/metadata/android --source app/src
# Specific scanners only
gpc preflight manifest app.aab
gpc preflight permissions app.aab
gpc preflight metadata ./metadata
gpc preflight codescan ./src
# CI mode
gpc preflight app.aab --fail-on error --json
9 scanners
| Scanner | Checks | Severity |
|---|---|---|
| manifest | targetSdk >= 36 (v0.9.79+), debuggable, testOnly (reads from <application> element since v0.9.80), cleartext, missing exported, FGS types, geofencing foreground service (v0.9.65+) |
critical/error/warning |
| permissions | 18 restricted permissions, contacts broad-access, Health Connect granular (v0.9.65+), Data Safety reminders | critical/error/warning/info |
| native-libs | 64-bit ARM compliance, ABI detection, 16KB page alignment (AAB + APK since v0.9.80, ELF header read 4096 bytes) | critical/warning |
| metadata | Listing character limits, screenshots, privacy policy URL | error/warning |
| secrets | AWS keys, Google API keys, Stripe keys, private keys | critical/warning |
| billing | Stripe, Braintree, PayPal, Razorpay SDK detection | warning |
| privacy | Tracking SDKs, Advertising ID, data collection cross-reference | warning/info |
| policy | Families/COPPA, financial, health, UGC, overlay | warning/info |
| size | Download size, large native libs, large assets | warning/info |
Configuration (.preflightrc.json)
{
"failOn": "error",
"targetSdkMinimum": 36,
"maxDownloadSizeMb": 150,
"allowedPermissions": ["android.permission.READ_SMS"],
"disabledRules": ["cleartext-traffic"],
"severityOverrides": { "billing-stripe-sdk": "info" }
}
API level 36 (Android 16) is required by August 31, 2026 for all new apps and updates on Google Play. The targetSdkMinimum default in GPC preflight was updated to 36 in v0.9.79 to reflect this deadline.
Exit codes
0— all checks passed1— runtime error6— findings at or above--fail-onseverity
Key rules
| Rule ID | Severity | What |
|---|---|---|
| targetSdk-below-minimum | critical | targetSdkVersion < 36 |
| debuggable-true | critical | android:debuggable="true" |
| testOnly-true | critical | android:testOnly="true" |
| missing-arm64 | critical | 32-bit ARM without 64-bit |
| missing-exported | error | Component with intent-filter but no exported attr |
| foreground-service-type-missing | error | Service without foregroundServiceType (API 34+) |
| secret-aws-key | critical | AWS access key in source |
| secret-stripe-key | critical | Stripe secret key in source |
| contacts-permission-broad | warning | READ_CONTACTS / WRITE_CONTACTS (v0.9.65+, April 2026 policy) |
| geofencing-foreground-service | warning | Location FGS + ACCESS_BACKGROUND_LOCATION (v0.9.65+, April 2026 policy) |
| health-connect-granular | warning/info | READ_ALL_HEALTH_DATA; warning on targetSdk >= 36, info otherwise (v0.9.65+, April 2026 policy) |
| policy-app-content-declaration | info | Any FOREGROUND_SERVICE* permission; reminder that Play Console -> Policy -> App content needs the matching declaration (v0.9.94+) |
Procedures
Running a full preflight scan
- Build your AAB or APK:
./gradlew bundleRelease(orassembleReleasefor APK) - Run:
gpc preflight app/build/outputs/bundle/release/app-release.aabOr for APK:gpc preflight app/build/outputs/apk/release/app-release.apk - Fix any critical/error findings
- Add a
.preflightrc.jsonto allow approved permissions or disable false positives - Re-run until clean
Note: After the scan, GPC shows a reminder about Android developer verification requirements (September 30, 2026 enforcement for BR, ID, SG, TH). Run gpc verify for details.
Since v0.9.80, the result JSON includes a skippedScanners array when scanners are filtered out (e.g., manifest-dependent scanners skipped due to manifest parse failure). This replaces the previous behavior where skipped scanners were silently omitted.
Signing key consistency (v0.9.66+)
gpc preflight signing # Check cert consistency across two most recent bundles
gpc preflight signing --json # JSON output for CI
gpc preflight signing --app com.example.app # Override package name
Compares signing certificates across your two most recent bundle versions via the Play API (generatedApks.list). Requires auth (service account or OAuth). Exit code 6 on mismatch (same as other preflight threshold breaches). Exit code 4 on API errors.
This is NOT an offline scan. It calls the Play API to create an edit, list bundles, fetch generated APKs for the top two version codes, compare certificateSha256Fingerprint, then delete the edit.
April 2026 policy rules (v0.9.65+)
Three rules added for Google Play's April 15, 2026 policy batch. Compliance deadline: May 15, 2026.
Contacts broad access (
contacts-permission-broad): Flags READ_CONTACTS / WRITE_CONTACTS. Google now requires the Android Contact Picker instead of broad access. Emits a single finding even when both permissions are present. Suppress viaallowedPermissionsfor dialer/messaging apps.Geofencing foreground service (
geofencing-foreground-service): Fires when a service hasforegroundServiceTypecontaining "location" AND the app declaresACCESS_BACKGROUND_LOCATION. Google removed geofencing as an approved foreground service use case. For legitimate background location tracking (navigation, fitness), suppress via"disabledRules": ["geofencing-foreground-service"].Health Connect granular permissions (
health-connect-granular): FlagsREAD_ALL_HEALTH_DATA. Severity iswarningwhentargetSdk >= 36(Android 16 requirement),infootherwise. Replace with granular permissions likehealth.READ_STEPS,health.READ_HEART_RATE, etc.
App content declaration advisory (v0.9.94+)
policy-app-content-declaration fires at info severity whenever the AAB requests any FOREGROUND_SERVICE* permission, listing which ones. It is a reminder that Play Console → Policy → App content needs the matching "Foreground service permissions" declaration completed before Google will accept a release.
Why it can only advise: the declaration is stored in Play Console and is not exposed through the Publisher API or readable from the bundle. Preflight can see that your app requests the permissions; it cannot see whether you filled in the form. It therefore never fails a run, regardless of --fail-on.
This is not the same check as foreground-service-type-missing. That one verifies android:foregroundServiceType is present on your <service> elements, which is a manifest requirement. You can have every service correctly typed and still be blocked at upload by the missing Console declaration — that combination is exactly what motivated this rule.
If the declaration is incomplete, the upload fails with API_DECLARATION_REQUIRED (v0.9.94+). Before v0.9.94 the same failure was reported as a service account permission problem, which sent people to Users and permissions instead of App content.
One finding is emitted per scan, not one per permission.
False-negative fixes (v0.9.80)
Four scanner accuracy improvements shipped in v0.9.80:
testOnlyattribute source: ThetestOnlyscanner now readsandroid:testOnlyfrom the<application>element of the manifest. Previously it was incorrectly reading from the<manifest>root, causing the check to always report no finding even whentestOnly="true"was set on the application.16KB alignment scanner scope: The 16KB page alignment scanner now checks native libraries inside APKs in addition to AABs. Previously it only inspected AAB artifacts, leaving APK native libraries unscanned.
ELF header read size: The ELF header reader was increased from 256 bytes to 4096 bytes. Small reads were insufficient for some native library formats, causing alignment checks to be skipped silently.
skippedScannersin results: Scanners that are disabled viaskippedScanners(or skipped due to missing inputs) are now reported in the scan result JSON under askippedScannersarray. This makes it visible in CI when a scanner did not run.
Adding to CI
# GitHub Actions
- name: Preflight
run: gpc preflight app.aab --fail-on error --json > preflight.json
- name: Upload report
if: always()
uses: actions/upload-artifact@v4
with:
name: preflight-report
path: preflight.json
Related skills
gpc-release-flow— uploading and releasing after preflight passesgpc-ci-integration— CI/CD patterns including preflight gatesgpc-troubleshooting— exit code 6 handlinggpc-security— credential handling and key rotation