extract-spark-meetings
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it retrieves and processes content from external URLs provided by the user.
- Ingestion points: Meeting content is fetched from
share.sparkmailapp.comlinks viaWebFetchor browser-automation tools. - Capability inventory: The skill possesses
WriteandEditcapabilities to create and update local files (spark-meetings/andlinks.md). - Boundary markers: The instructions do not specify the use of delimiters or specific "ignore" instructions when the agent processes the fetched meeting transcript.
- Sanitization: There is no explicit requirement for the agent to sanitize the fetched HTML/text before parsing it into meeting fields.
- Context: This risk is inherent to the skill's primary function of web extraction and is considered a standard operational characteristic rather than a malicious defect.
Audit Metadata