spark-persona-sales-rep

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is provided by the vendor (readdle) to enhance the functionality of their Spark email client, and its operations are limited to standard email management tasks.
  • [COMMAND_EXECUTION]: The skill instructions leverage the spark command-line utility for operations like searching, reading, and drafting emails, which is the authorized method for this service.
  • [PROMPT_INJECTION]: The skill reads external email content, presenting an indirect prompt injection surface. 1) Ingestion points: spark thread and spark search in SKILL.md. 2) Boundary markers: None. 3) Capability inventory: spark draft and spark action (reminder/pin) in SKILL.md. 4) Sanitization: The instructions include a manual safety check by requiring the agent to confirm all drafts with the user.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 01:15 PM