extract-spark-meetings

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it retrieves and processes content from external URLs provided by the user.
  • Ingestion points: Meeting content is fetched from share.sparkmailapp.com links via WebFetch or browser-automation tools.
  • Capability inventory: The skill possesses Write and Edit capabilities to create and update local files (spark-meetings/ and links.md).
  • Boundary markers: The instructions do not specify the use of delimiters or specific "ignore" instructions when the agent processes the fetched meeting transcript.
  • Sanitization: There is no explicit requirement for the agent to sanitize the fetched HTML/text before parsing it into meeting fields.
  • Context: This risk is inherent to the skill's primary function of web extraction and is considered a standard operational characteristic rather than a malicious defect.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 07:45 PM
Security Audit — agent-trust-hub — extract-spark-meetings