quiz
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and read the full content of documents from the Readwise Reader service. Since this content is sourced from the web or user-curated documents, it represents an attack surface for indirect prompt injection where malicious instructions within the text could attempt to override the agent's behavior during the quiz.
- [COMMAND_EXECUTION]: The skill uses the
readwiseCLI to perform searches and retrieve document data if MCP tools are unavailable. These commands are restricted to the official tool's subcommands (list,read,search) and are central to the skill's primary purpose. - [SAFE]: The skill reads a local file named
reader_persona.mdto personalize its interactions. This access is specific to the working directory and aligns with the setup instructions for user personalization.
Audit Metadata