triage
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to use the
readwiseCLI as a fallback for listing, reading, and moving documents if MCP tools are not available. This is standard functionality for interacting with the Readwise service. - [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from the Readwise service, which represents a potential surface for indirect prompt injection. 1. Ingestion points: Document titles, summaries, and full text content are fetched from the Readwise API in SKILL.md. 2. Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the fetched document text. 3. Capability inventory: The skill has the ability to archive and move documents using MCP tools and CLI commands. 4. Sanitization: No sanitization or validation steps for the fetched document content are defined in the triage loop.
Audit Metadata