spark-recipe-schedule-meeting

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes using the spark command-line utility to query contacts and availability. These commands are instructional and rely on a pre-existing environment where the 'spark' tool is available, typically provided by the 'use-spark' base skill mentioned in the metadata.
  • [DATA_EXPOSURE]: The skill instructions involve reading contact emails and calendar availability. This access is consistent with the skill's stated purpose of finding meeting times and is marked as 'read-only' in the metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes output from calendar and contact queries. While this data originates from potentially untrusted sources (e.g., shared calendar events), the skill currently only facilitates displaying time slots, which is a low-risk operation. The documentation does not provide specific boundary markers for this data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:07 PM
Security Audit — agent-trust-hub — spark-recipe-schedule-meeting