reader-recap
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external content including document titles, highlights, and user notes retrieved via the Readwise API or CLI, as well as a local
reader_persona.mdfile. This data ingestion surface could be exploited if malicious instructions are embedded within the synced reading material or annotations. - Ingestion points: Readwise document data (Step 1 & 2), highlight notes (Step 3), and
reader_persona.md(Setup). - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content within the fetched data.
- Capability inventory: The skill is restricted to read-only operations using vendor-specific Readwise tools and local file reading; it does not possess capabilities for file writing, system modification, or external network exfiltration.
- Sanitization: No specific sanitization or filtering logic is defined for the external content before it is interpolated into the summary prompt.
- [COMMAND_EXECUTION]: The instructions specify the use of the
readwiseCLI as a fallback mechanism for retrieving data. This involves executing system commands such asreadwise list,readwise read <id>, andreadwise highlights <id>. These are official vendor tools for the Readwise service.
Audit Metadata