readwise-mcp
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external content and possesses the capability to modify user data.
- Ingestion points: The agent fetches potentially untrusted data from scraped web articles, PDFs, and RSS feeds via the
reader_get_document_detailsandreader_list_documentstools. - Boundary markers: The instructions do not define any delimiters or explicit boundary markers to help the agent distinguish between administrative instructions and the external content being processed.
- Capability inventory: The skill includes several tools that allow the agent to modify the user's library, such as
readwise_delete_highlight,reader_move_documents, andreader_bulk_edit_document_metadata. - Sanitization: There is no description of content sanitization or validation processes to filter out embedded instructions within the documents before they are read by the agent.
Audit Metadata