now-reading-page

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes document metadata (titles, authors, and source names) fetched from the user's Readwise account to generate a webpage. While this involves ingesting external data, the process is central to the skill's primary functionality.
  • Ingestion points: Metadata is retrieved from the Readwise service via MCP tools or the readwise CLI as defined in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded instructions within the fetched metadata are provided.
  • Capability inventory: The skill is capable of writing local files (now-reading/index.html) and executing CLI commands to interact with the environment.
  • Sanitization: The skill does not explicitly detail sanitization procedures for the metadata before it is interpolated into the generated HTML file.
  • [COMMAND_EXECUTION]: The instructions utilize the readwise CLI for data access and the open command to display the generated HTML file in a web browser. These are standard operations necessary for the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: The generated HTML file includes references to Google Fonts (Newsreader and DM Sans) using standard <link> tags, which is a common and trusted practice for web styling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:50 AM
Security Audit — agent-trust-hub — now-reading-page