spark-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install spark-history-cli via pip. This tool is the primary mechanism for the skill's functionality and is a resource associated with the skill's author (yaooqinn).
  • [COMMAND_EXECUTION]: The skill operates by executing shell commands using the spark-history-cli tool to retrieve structured JSON data about Spark applications, including SQL plans, stage summaries, and executor metrics.
  • [DYNAMIC_EXECUTION]: The provided bash script sample_codes/compare-apps.sh uses python -c to execute small Python snippets for parsing JSON data. This is a standard method for processing structured CLI output within a shell environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and analyzes data (such as SQL query descriptions) from an external Spark History Server which could be influenced by an attacker.
  • Ingestion points: Data is retrieved from local or remote Spark History Server instances via spark-history-cli tool calls.
  • Boundary markers: The skill uses the --json flag to ensure data is handled in a structured format, which helps reduce accidental misinterpretation of content.
  • Capability inventory: The skill has the ability to execute the spark-history-cli tool and write diagnostic reports to the local file system as Markdown files.
  • Sanitization: There is no explicit sanitization step for metrics or descriptions fetched from the Spark History Server before they are included in the final generated report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:50 PM
Security Audit — agent-trust-hub — spark-advisor