book-review

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user's Readwise library, specifically through the mcp__readwise__reader_get_document_highlights tool. This text (highlights and user-provided notes) is processed to extract claims and draft a review. There are no boundary markers or explicit instructions to ignore embedded commands within this data. The agent possesses the capability to write back to the user's library via mcp__readwise__reader_create_document, creating a risk where malicious text in a highlight could trigger unauthorized document creation or context manipulation.
  • Ingestion points: SKILL.md calls mcp__readwise__reader_get_document_highlights to pull arbitrary text from external document highlights.
  • Boundary markers: Absent; the agent is instructed to read the text directly to extract claims.
  • Capability inventory: mcp__readwise__reader_create_document (file write), mcp__readwise__reader_search_documents (data access), and local file read for reader_persona.md.
  • Sanitization: Absent; the skill relies on the LLM to summarize and critique the content without prior filtering.
  • [COMMAND_EXECUTION]: The skill instructions provide a fallback mechanism to execute readwise CLI commands (e.g., readwise search, readwise read) if MCP tools are not available. While these are tools provided by the vendor, they involve executing shell commands on the host environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:45 PM
Security Audit — agent-trust-hub — book-review