reader-recap

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content including document titles, highlights, and user notes retrieved via the Readwise API or CLI, as well as a local reader_persona.md file. This data ingestion surface could be exploited if malicious instructions are embedded within the synced reading material or annotations.
  • Ingestion points: Readwise document data (Step 1 & 2), highlight notes (Step 3), and reader_persona.md (Setup).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content within the fetched data.
  • Capability inventory: The skill is restricted to read-only operations using vendor-specific Readwise tools and local file reading; it does not possess capabilities for file writing, system modification, or external network exfiltration.
  • Sanitization: No specific sanitization or filtering logic is defined for the external content before it is interpolated into the summary prompt.
  • [COMMAND_EXECUTION]: The instructions specify the use of the readwise CLI as a fallback mechanism for retrieving data. This involves executing system commands such as readwise list, readwise read <id>, and readwise highlights <id>. These are official vendor tools for the Readwise service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:50 AM
Security Audit — agent-trust-hub — reader-recap