book-review
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user's Readwise library, specifically through the
mcp__readwise__reader_get_document_highlightstool. This text (highlights and user-provided notes) is processed to extract claims and draft a review. There are no boundary markers or explicit instructions to ignore embedded commands within this data. The agent possesses the capability to write back to the user's library viamcp__readwise__reader_create_document, creating a risk where malicious text in a highlight could trigger unauthorized document creation or context manipulation. - Ingestion points: SKILL.md calls
mcp__readwise__reader_get_document_highlightsto pull arbitrary text from external document highlights. - Boundary markers: Absent; the agent is instructed to read the text directly to extract claims.
- Capability inventory:
mcp__readwise__reader_create_document(file write),mcp__readwise__reader_search_documents(data access), and local file read forreader_persona.md. - Sanitization: Absent; the skill relies on the LLM to summarize and critique the content without prior filtering.
- [COMMAND_EXECUTION]: The skill instructions provide a fallback mechanism to execute
readwiseCLI commands (e.g.,readwise search,readwise read) if MCP tools are not available. While these are tools provided by the vendor, they involve executing shell commands on the host environment.
Audit Metadata