spark-recipe-vacation-catchup
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading email threads, creating a surface for indirect prompt injection.
- Ingestion points:
SKILL.md(Step 3) usesspark thread <id>to read email content. - Boundary markers: Absent. There are no instructions or delimiters provided to prevent the agent from executing instructions found within email bodies.
- Capability inventory: The skill utilizes
spark action archive,spark contact-action blockContact, andspark action snoozeinSKILL.md. - Sanitization: Absent. No mention of content sanitization or filtering is present.
Audit Metadata