use-spark

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated Spark email/calendar purpose and uses the vendor's local Spark CLI rather than routing data to an unrelated third-party endpoint. However, it grants high-impact mailbox and scheduling actions, includes a self-updating skill rewrite path, and installation/update trust is only moderately verifiable through same-org GitHub and Spark docs rather than stronger signed release artifacts. This is not confirmed malware, but it is a medium-risk agent skill due to real-world action capability and transitive trust.

Confidence: 90%Severity: 57%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/readdle%2Fspark-cli-skills%2Fuse-spark%2F@ca4e0309f0bc593af7bb65dc364f63be56233862754628199127a47a5cd0a437
Security Audit — socket — use-spark