highlight-graph
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes highlights fetched from the Readwise API, which may contain attacker-controlled content if highlights are sourced from untrusted documents.
- Ingestion points: Highlights are retrieved via
readwise_list_highlightsandreadwise_search_highlightsinSKILL.md. - Boundary markers: The instructions for subagents finding semantic connections do not include explicit boundaries or instructions to ignore potential commands embedded in highlight text.
- Capability inventory: The skill writes data to temporary JSON files, executes a Python script to generate HTML, and opens the resulting file in a web browser.
- Sanitization: The visualization script (
build_graph.py) does not escape HTML characters in thesource_titleandsource_authorfields when generating the legend, which could lead to XSS if a highlight source title contains malicious code. - [EXTERNAL_DOWNLOADS]: The generated HTML visualization fetches the
force-graphlibrary from theunpkg.comCDN, which is a well-known service for hosting JavaScript packages.
Audit Metadata