now-reading-page
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes document metadata (titles, authors, and source names) fetched from the user's Readwise account to generate a webpage. While this involves ingesting external data, the process is central to the skill's primary functionality.
- Ingestion points: Metadata is retrieved from the Readwise service via MCP tools or the
readwiseCLI as defined inSKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded instructions within the fetched metadata are provided.
- Capability inventory: The skill is capable of writing local files (
now-reading/index.html) and executing CLI commands to interact with the environment. - Sanitization: The skill does not explicitly detail sanitization procedures for the metadata before it is interpolated into the generated HTML file.
- [COMMAND_EXECUTION]: The instructions utilize the
readwiseCLI for data access and theopencommand to display the generated HTML file in a web browser. These are standard operations necessary for the skill's stated purpose. - [EXTERNAL_DOWNLOADS]: The generated HTML file includes references to Google Fonts (Newsreader and DM Sans) using standard
<link>tags, which is a common and trusted practice for web styling.
Audit Metadata