feed-catchup
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external content from RSS feeds, including titles, summaries, and full article text, which could contain instructions designed to manipulate the agent's behavior. The agent reads this untrusted data and uses it to generate summaries and commentary.
- Ingestion points: The skill fetches document metadata and full content via
mcp__readwise__reader_list_documentsandmcp__readwise__reader_get_document_details(or CLI equivalents) inSKILL.md. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when presenting external feed content to the model.
- Capability inventory: The skill has the ability to move, archive, and mark documents as seen via MCP tools or CLI commands, as well as fetch full content for any document in the feed.
- Sanitization: The skill does not perform any sanitization or validation of the text returned from the Readwise API/CLI before processing it.
Audit Metadata