spark-recipe-draft-batch
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the
sparktool for its intended purpose of email management. No unauthorized data access, network exfiltration, or credential harvesting patterns were detected. - [PROMPT_INJECTION]: The skill reads email content, which is an external ingestion point for potential indirect prompt injection. This is considered safe as the workflow requires human review of each decision. 1. Ingestion points: Email threads via
spark thread <id>inSKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Draft editing and deletion viasparkcommands inSKILL.md. 4. Sanitization: None.
Audit Metadata