spark-persona-founder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external email content via the
spark emailsandspark searchcommands. Although this represents an attack surface where untrusted data could influence the agent, the skill instructions specifically require the agent to confirm drafts with the user before creation, providing a necessary security boundary. - [COMMAND_EXECUTION]: The skill utilizes the
sparkcommand-line utility to interact with the user's inbox. The commands provided (triage, delegate, snooze, archive, and draft) are all within the expected scope of the tool's functionality for managing email communications.
Audit Metadata