highlight-graph

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes highlights fetched from the Readwise API, which may contain attacker-controlled content if highlights are sourced from untrusted documents.
  • Ingestion points: Highlights are retrieved via readwise_list_highlights and readwise_search_highlights in SKILL.md.
  • Boundary markers: The instructions for subagents finding semantic connections do not include explicit boundaries or instructions to ignore potential commands embedded in highlight text.
  • Capability inventory: The skill writes data to temporary JSON files, executes a Python script to generate HTML, and opens the resulting file in a web browser.
  • Sanitization: The visualization script (build_graph.py) does not escape HTML characters in the source_title and source_author fields when generating the legend, which could lead to XSS if a highlight source title contains malicious code.
  • [EXTERNAL_DOWNLOADS]: The generated HTML visualization fetches the force-graph library from the unpkg.com CDN, which is a well-known service for hosting JavaScript packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:50 AM
Security Audit — agent-trust-hub — highlight-graph