spark-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions and code templates for building distributed data processing pipelines, which creates a potential surface for indirect prompt injection attacks.
- Ingestion points: The skill guides the agent to read data from various untrusted external sources, including cloud storage buckets (
spark.read.parquet), distributed file systems (spark.sparkContext.textFile), and streaming platforms (spark.readStreamfrom Kafka). - Boundary markers: The instructions emphasize the use of explicit schema definitions for production pipelines (as seen in
SKILL.mdandreferences/spark-sql-dataframes.md). This provides structural validation but lacks specific guidance on using prompt delimiters or instructions to ignore embedded natural language commands within the processed data. - Capability inventory: The skill enables the agent to generate code with powerful capabilities, including writing to file systems (
df.write), interacting with external databases via JDBC, and managing Kafka stream offsets. - Sanitization: The instructions focus on structural integrity and performance tuning. There is no specific guidance provided for sanitizing or escaping the content of processed data to prevent malicious instructions from affecting the agent if it analyzes the output or logs of these Spark jobs.
Audit Metadata