readwise-cli

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @readwise/cli package from the public npm registry. This is a vendor-owned package necessary for the skill's primary functionality.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the readwise CLI to perform operations such as searching documents, fetching highlights, and creating new content. This includes a login-with-token command that requires the user to provide an API access token from their Readwise account.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from the user's reading library, such as articles and RSS feeds. This content is ingested into the agent's context through commands like reader-get-document-details and reader-get-document-highlights. While the skill has the capability to write back to the service (e.g., creating documents or highlights), the risk of content influencing the agent is inherent to the intended use case of reading external articles.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:22 AM
Security Audit — agent-trust-hub — readwise-cli