triage

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to use the readwise CLI as a fallback for listing, reading, and moving documents if MCP tools are not available. This is standard functionality for interacting with the Readwise service.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from the Readwise service, which represents a potential surface for indirect prompt injection. 1. Ingestion points: Document titles, summaries, and full text content are fetched from the Readwise API in SKILL.md. 2. Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the fetched document text. 3. Capability inventory: The skill has the ability to archive and move documents using MCP tools and CLI commands. 4. Sanitization: No sanitization or validation steps for the fetched document content are defined in the triage loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:50 AM
Security Audit — agent-trust-hub — triage