spark
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and synthesize data from external sources (such as user feedback, metrics, and competitive analysis) into product specifications, creating a potential surface for indirect prompt injection where malicious inputs could influence the agent's output.
- Ingestion points: Untrusted data is ingested through the Pulse (usage metrics), Voice (user feedback), and Compete (competitive gaps) modules, as specified in the collaboration patterns defined in
SKILL.md. - Boundary markers: The instructions do not prescribe explicit delimiters (e.g., [BEGIN DATA]) or specific warnings to ignore instructions embedded within these external inputs.
- Capability inventory: The agent has the ability to write documents to the filesystem and execute shell commands for subagent orchestration as described in the
multirecipe. - Sanitization: The framework relies on human-led judgment and review stages (mentioned in
reference/modern-product-discovery.md) but lacks automated data sanitization or escaping mechanisms. - [COMMAND_EXECUTION]: The skill's 'multi' recipe involves the use of external CLI tools and instructs the agent to perform environment discovery using shell commands.
- Evidence:
reference/tri-engine-proposal.mdcontains a shell script for the agent to execute to detect the presence of tools likecodex,agy, andclaudeby probing paths such as/usr/local/bin/and running version checks.
Audit Metadata