spark-recipe-topic-timeline
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to access sensitive information, including email thread bodies and meeting transcripts, using the
sparkCLI. This data access is aligned with the skill's primary objective of historical narrative construction. - [COMMAND_EXECUTION]: The instructions rely on the execution of shell commands such as
spark meetings,spark meeting,spark search, andspark threadto retrieve data from the Spark environment. - [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing untrusted data from external communication channels.
- Ingestion points: Meeting transcripts and email message bodies fetched from the user's account via the
sparktool. - Boundary markers: Absent; there are no instructions to use delimiters (e.g., XML tags) or specific prompts directing the model to ignore instructions contained within the fetched content.
- Capability inventory: The skill facilitates data retrieval and summarization but does not include capabilities for file system modification or outbound network requests to non-vendor domains.
- Sanitization: No sanitization or filtering logic is present to identify or neutralize adversarial content within the retrieved emails or meetings.
Audit Metadata