spark-persona-founder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external email content via the spark emails and spark search commands. Although this represents an attack surface where untrusted data could influence the agent, the skill instructions specifically require the agent to confirm drafts with the user before creation, providing a necessary security boundary.
  • [COMMAND_EXECUTION]: The skill utilizes the spark command-line utility to interact with the user's inbox. The commands provided (triage, delegate, snooze, archive, and draft) are all within the expected scope of the tool's functionality for managing email communications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:08 PM
Security Audit — agent-trust-hub — spark-persona-founder