spark-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Automated security scans (URLite) detected that the documentation URL
https://jeffallan.github.io/claude-skills/skills/data-ml/spark-engineer/referenced in the skill is currently blacklisted. While the URL points to a vendor-controlled GitHub Pages site, the negative reputation hit indicates a potential risk if the external site was compromised. - [METADATA_POISONING]: The skill's metadata and frontmatter include a link to documentation that has been flagged as malicious by file reputation scanners, which could lead users to interact with blacklisted web resources.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a code generation agent for Spark applications, which constitutes an indirect prompt injection surface. It ingests untrusted user requirements to produce executable Spark code without explicit sanitization mechanisms. * Ingestion points: User requirements and transformation descriptions processed by the agent using SKILL.md. * Boundary markers: The 'Constraints' section provides rules for the AI, but no technical delimiters are used for user-supplied data. * Capability inventory: Generation of Spark SQL, PySpark, and Scala RDD code, as well as cluster configuration parameters. * Sanitization: No explicit sanitization or validation of user-provided schema or transformation logic is documented.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata