readwise-cli
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@readwise/clipackage from the public npm registry. This is a vendor-owned package necessary for the skill's primary functionality. - [COMMAND_EXECUTION]: The skill makes extensive use of the
readwiseCLI to perform operations such as searching documents, fetching highlights, and creating new content. This includes alogin-with-tokencommand that requires the user to provide an API access token from their Readwise account. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from the user's reading library, such as articles and RSS feeds. This content is ingested into the agent's context through commands like
reader-get-document-detailsandreader-get-document-highlights. While the skill has the capability to write back to the service (e.g., creating documents or highlights), the risk of content influencing the agent is inherent to the intended use case of reading external articles.
Audit Metadata