read-weread-analyzer

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified. The skill ingests user-generated notes and reviews from WeRead to produce complex analysis without sanitization or boundary markers. (Ingestion points: book metadata and reviews from i.weread.qq.com; Boundary markers: None; Capability inventory: Python execution, file writing, browser launching; Sanitization: None).
  • [COMMAND_EXECUTION]: The skill executes automated tasks via the command line. (Evidence: execution of local fetch.py script, directory creation with mkdir, and report launching via system browser commands).
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from a remote service. (Evidence: fetches reading data and notebook content from the official WeRead API at i.weread.qq.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 03:51 PM
Security Audit — agent-trust-hub — read-weread-analyzer