spark-persona-team-lead
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions and examples for using the
sparkCLI to manage shared inboxes and team assignments. All operations are consistent with the skill's stated purpose. - [COMMAND_EXECUTION]: The skill instructs the agent to execute
sparkcommands for listing teams, reading emails, and performing actions like assignments or comments. These are documented tools for the Spark platform and do not involve arbitrary shell execution or system modification. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from email bodies via the
spark threadcommand. - Ingestion points: Email content is read using
spark thread <id>inSKILL.md. - Boundary markers: None identified.
- Capability inventory: The skill can perform assignments (
spark action assign), modify status (spark action markAsDone), and add comments (spark comment) based on the content read. - Sanitization: No specific sanitization or filtering of email content is described.
- Assessment: This is a low-risk surface inherent to the skill's primary function of email triage.
Audit Metadata