readwise-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external content and possesses the capability to modify user data.
  • Ingestion points: The agent fetches potentially untrusted data from scraped web articles, PDFs, and RSS feeds via the reader_get_document_details and reader_list_documents tools.
  • Boundary markers: The instructions do not define any delimiters or explicit boundary markers to help the agent distinguish between administrative instructions and the external content being processed.
  • Capability inventory: The skill includes several tools that allow the agent to modify the user's library, such as readwise_delete_highlight, reader_move_documents, and reader_bulk_edit_document_metadata.
  • Sanitization: There is no description of content sanitization or validation processes to filter out embedded instructions within the documents before they are read by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:50 AM
Security Audit — agent-trust-hub — readwise-mcp