quiz

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and read the full content of documents from the Readwise Reader service. Since this content is sourced from the web or user-curated documents, it represents an attack surface for indirect prompt injection where malicious instructions within the text could attempt to override the agent's behavior during the quiz.
  • [COMMAND_EXECUTION]: The skill uses the readwise CLI to perform searches and retrieve document data if MCP tools are unavailable. These commands are restricted to the official tool's subcommands (list, read, search) and are central to the skill's primary purpose.
  • [SAFE]: The skill reads a local file named reader_persona.md to personalize its interactions. This access is specific to the working directory and aligns with the setup instructions for user personalization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:38 AM
Security Audit — agent-trust-hub — quiz