spark-engineer

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a blacklisted malicious domain jeffallan.github.io in its documentation and author fields. Specifically, automated security scans have identified https://jeffallan.github.io/claude-skills/skills/data-ml/spark-engineer/ as a malicious URL. Furthermore, the skill's primary instruction file SKILL.md has been flagged as malware by file reputation scanners.\n- [METADATA_POISONING]: There is a significant discrepancy between the author name Jeffallan provided in the skill's YAML frontmatter and the internal developer attribution to sodiqabdulwaris. This use of conflicting identities is often associated with deceptive or malicious content distribution.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted technical requirements (such as transformation logic and data schemas) to generate and optimize Spark implementation code. It lacks explicit boundary markers, sanitization instructions, or specific directives to ignore potentially malicious commands embedded within these requirements, creating a surface for indirect prompt injection attacks.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — spark-engineer