spark-recipe-newsletter-cleanup

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The recipe's capabilities mostly match its stated purpose, but its trust chain is incomplete because it relies on an unseen `use-spark` skill and an unverified `spark` CLI command surface. Data flows are broadly consistent with Spark's official product features, including AI summaries, yet enabling summaries can send email content to Spark and an external AI provider. Overall this looks more like a legitimate-but-underverified mailbox automation recipe than malware, with medium risk driven by undocumented execution trust and real mailbox actions.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 8, 2026, 01:17 PM
Package URL
pkg:socket/skills-sh/readdle%2Fspark-cli-skills%2Fspark-recipe-newsletter-cleanup%2F@b38b95263b5370d3a0562d5cb332046e29b5cdb6