Skip to content
Back to skills

Google Play Store

ASecurity

Publish, optimize, and scale Android apps on Google Play with release automation, ASO, policy compliance, and rejection recovery.

  • 14 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 7, 2026
securitygotestingapici/cdsecuritydocumentation

Works with

  • api

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill google-play-store --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Google Play Store?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Google Play Store
[![Security: A โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-google-play-store/badge)](https://www.skillsdirectory.com/skills/modbender-google-play-store)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Google Play Store
slug: google-play-store
version: 1.0.0
homepage: https://clawic.com/skills/google-play-store
description: Publish, optimize, and scale Android apps on Google Play with release automation, ASO, policy compliance, and rejection recovery.
metadata: {"clawdbot":{"emoji":"๐Ÿค–","requires":{"bins":[]},"os":["linux","darwin","win32"]}}
---

## Setup

On first use, read `setup.md` for integration guidelines.

## When to Use

User needs to publish, manage, or optimize Android apps on Google Play. Agent handles release workflows, store optimization, policy compliance, review processes, and rejection troubleshooting.

## Architecture

Memory lives in `~/google-play-store/`. See `memory-template.md` for structure.

```
~/google-play-store/
โ”œโ”€โ”€ memory.md         # Account, apps, preferences
โ”œโ”€โ”€ apps/             # Per-app tracking
โ”‚   โ””โ”€โ”€ {package}/    # Package-specific notes
โ””โ”€โ”€ checklists/       # Saved submission checklists
```

## Quick Reference

| Topic | File |
|-------|------|
| Setup process | `setup.md` |
| Memory template | `memory-template.md` |
| Release tracks and rollouts | `tracks.md` |
| App Store Optimization | `aso.md` |
| Policy compliance | `policies.md` |
| Rejection recovery | `rejections.md` |
| Automation with Fastlane | `fastlane.md` |

## Core Rules

### 1. Release Track Progression

| Track | Purpose | Review | Users |
|-------|---------|--------|-------|
| Internal | Daily builds, QA | None | 100 max |
| Closed | Beta testers | 2-6h | Email list |
| Open | Public beta | 2-6h | Anyone joins |
| Production | Full release | 2-24h | Everyone |

**Mandatory progression for new apps:**
```
Internal โ†’ Closed (20+ testers, 14+ days) โ†’ Production
```

Skip this = instant rejection. Start closed testing on day one.

### 2. Pre-Submission Checklist

Run before EVERY submission:

```
CONTENT
[ ] Privacy policy URL live and HTTPS
[ ] Data safety form 100% complete
[ ] Content rating questionnaire done
[ ] All screenshots show real app (no placeholders)
[ ] Feature graphic 1024x500 uploaded

TECHNICAL
[ ] Target SDK โ‰ฅ 34 (Android 14)
[ ] versionCode higher than ALL previous uploads
[ ] Signed with correct key
[ ] No hardcoded API keys in code
[ ] ProGuard/R8 not breaking functionality

TESTING (new apps only)
[ ] 20+ testers opted in (not just invited)
[ ] 14+ consecutive days completed
[ ] Crash-free rate > 99%
```

### 3. Version Code Strategy

```
versionCode must ALWAYS increase. Cannot reuse. Ever.

Pattern: YYYYMMDDHH
Example: 2025022514 (Feb 25, 2025, 2pm)

Why: Rejected uploads "burn" the versionCode.
     Multiple builds per day need unique codes.
```

### 4. App Signing Models

| Model | Control | Recovery | Best For |
|-------|---------|----------|----------|
| Google-managed | Google holds key | Easy | New apps |
| Upload key | You sign, Google re-signs | Medium | Most apps |
| Self-managed | Full control | Hard | Enterprise |

**Recommendation:** Google-managed for new apps. Upload key for updates.

**Critical:** Export and backup your upload key immediately after creating it.

### 5. Staged Rollout Protocol

| Stage | % | Duration | Gate |
|-------|---|----------|------|
| Canary | 1% | 24-48h | Crashes < 0.1% |
| Early | 5% | 48-72h | ANRs < 0.5% |
| Mid | 20% | 72-96h | Ratings stable |
| Late | 50% | 96-120h | No regressions |
| Full | 100% | โ€” | All clear |

**Halt triggers:** Crash spike, ANR spike, 1-star surge, critical bug reports.

### 6. ASO Essentials

| Element | Limit | Impact |
|---------|-------|--------|
| Title | 30 chars | Highest |
| Short description | 80 chars | High |
| Full description | 4000 chars | Medium |
| Screenshots | 8 per type | High |
| Feature graphic | 1024x500 | Medium |

**Keyword strategy:**
- Title: Primary keyword + brand
- Short desc: Top 3 keywords naturally
- Full desc: Long-tail throughout
- Update quarterly based on Search Console

### 7. Response Time SLAs

| Action | Google Response | Your Deadline |
|--------|-----------------|---------------|
| Policy email | 7 days to fix | Respond in 3 |
| Appeal | 3-7 days | Submit in 24h |
| Data request | 30 days | Complete in 14 |
| Critical issue | 24h suspension | Immediate |

**Rule:** Never ignore policy emails. Silence = admission.

## Common Traps

### Publishing Traps
- **Skipped closed testing** โ†’ Cannot release to production. 20 testers + 14 days mandatory for new apps.
- **Data safety incomplete** โ†’ Instant rejection. Fill EVERY field even if "no data collected."
- **Screenshots with mockups** โ†’ Rejection for misleading. Use real app screenshots only.
- **Privacy policy 404** โ†’ Rejection. Verify URL works before every submission.

### Technical Traps
- **versionCode not incremented** โ†’ Upload rejected. Even rejected uploads burn codes.
- **Target SDK too old** โ†’ Rejection. Check current requirement before building.
- **Forgot upload key password** โ†’ Cannot update app. Store password in password manager.
- **ProGuard broke app** โ†’ Crashes after release. Always test release build.

### Policy Traps
- **Undeclared permissions** โ†’ Policy violation. Justify EVERY sensitive permission.
- **Background location without need** โ†’ Rejection + strike. Remove or justify with video.
- **Kids content undeclared** โ†’ Policy violation. If ANY appeal to children, declare it.
- **Deceptive ads** โ†’ Suspension risk. Follow interstitial timing and close button rules.

### Business Traps
- **No staged rollout** โ†’ Bad update hits everyone. Always start at 1%.
- **Ignored policy email** โ†’ Escalation to strike. Respond within 3 days.
- **Multiple accounts to evade** โ†’ Termination. One violation becomes account death.

## Security & Privacy

**Data that stays local:**
- Package names and app status in ~/google-play-store/
- Submission checklists and workflow notes
- Release history and lessons learned

**This skill stores ONLY non-sensitive metadata:**
- App names and package identifiers
- Track status (internal/closed/production)
- Workflow preferences (manual vs CI/CD tool names)
- Checklist progress

**This skill does NOT store and will refuse:**
- API keys, service account JSON content
- Keystore files or passwords
- OAuth tokens or Play Console credentials
- Any secret or credential material

**This skill does NOT:**
- Upload apps or make network requests
- Access signing keys or certificates
- Execute Fastlane commands directly

User manages all credentials in their CI/CD system and runs commands themselves. The Fastlane examples are documentation only.

## Related Skills
Install with `clawhub install <slug>` if user confirms:
- `android` โ€” Android development
- `app-store` โ€” iOS and Android publishing
- `mobile` โ€” Cross-platform mobile

## Feedback

- If useful: `clawhub star google-play-store`
- Stay updated: `clawhub sync`

Files in this skill

  • SKILL.md6.9 KB
  • aso.md4.8 KB
  • fastlane.md6 KB
  • memory-template.md1.8 KB
  • policies.md5.7 KB
  • rejections.md5.6 KB
  • setup.md1.8 KB
  • tracks.md4.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ