Back to skill

Security audit

Readwise Official

Security checks for vulnerabilities and agentic risk

Overview

This Readwise skill matches its stated purpose, but needs review because it asks the agent to handle a raw access token, installs an unpinned global CLI, and includes account-changing commands without clear confirmation safeguards.

Review before installing. Use this only if you are comfortable giving the CLI broad access to your Readwise and Reader account. Prefer authenticating outside the agent or with a safer secret-entry method, avoid putting tokens in chat or command history, confirm any export, bulk edit, move, tag, update, or delete action before it runs, and consider using a pinned or local CLI install rather than an unpinned global npm install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14-18
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Medium

Vulnerable Code:

markdown
## Setup

If `readwise` is not installed:
```bash
npm install -g @readwise/cli
text

### Technical Analysis

The Skill directs the agent to retrieve the latest available version of `@readwise/cli` from npm and install it globally. It does not specify a reviewed version, lockfile, expected integrity hash, or other provenance verification mechanism.

npm packages can execute lifecycle scripts during installation. Because the effective package contents may change after this Skill has been audited, a compromised or unexpectedly modified package release could execute arbitrary code under the privileges of the user performing the installation. Global installation also increases the affected scope by placing executables and package files into shared user-level or system-level npm locations.

The audit found no evidence that the named package is currently malicious. The vulnerability is the Skill's unsafe dependency acquisition and installation practice.

### Attack Path

1. An attacker compromises the npm publisher account, package distribution channel, or a future release of `@readwise/cli`.
2. The attacker publishes a release containing malicious installation or runtime code.
3. An agent follows the Skill instructions and executes `npm install -g @readwise/cli`.
4. npm downloads the attacker-controlled current release without checking it against a version or integrity value approved by the Skill author.
5. Malicious lifecycle code may execute during installation, or malicious CLI code may execute when the `readwise` command is subsequently invoked.
6. The payload operates with the permissions of the installing user and may modify user-accessible files, credentials, or globally installed npm tooling.

### Impact Assess
...[truncated 389 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin @readwise/cli to a specific version that has been reviewed, rather than implicitly installing the latest release.
  • Record and verify the expected package integrity or provenance before installation.
  • Document the expected npm registry to reduce registry substitution and configuration-related supply-chain risks.
  • Prefer a project-local installation over a global installation so that the package is isolated and represented in a lockfile.
  • Commit an npm lockfile where applicable and use a reproducible installation mechanism such as npm ci.
  • Avoid elevated installation privileges and explicitly warn users not to run the installation through sudo.
  • Consider disabling lifecycle scripts with --ignore-scripts if the reviewed CLI can be installed and operated correctly without them.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Readwise Access Token Passed as a Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-24
Vulnerability Type: Sensitive credential exposure through process arguments and command logging
Risk Level: Medium

Vulnerable Code:

markdown
If not authenticated, ask the user for their Readwise access token (they can get one at https://readwise.io/access_token), then run:
```bash
readwise login-with-token <token>
text

### Technical Analysis

The Skill instructs the agent to interpolate a Readwise access token directly into a shell command. Secrets passed as command-line arguments may be exposed through shell history, process inspection, terminal capture, command auditing, debugging output, automation logs, or retained agent transcripts.

The instructions do not prescribe a protected input channel, prevent command logging, or require cleanup after authentication. Consequently, the token may remain available beyond the authentication operation and could be recovered by another local user, process, logging system, or person with access to the conversation transcript.

### Attack Path

1. The user supplies a valid Readwise access token to the agent as instructed.
2. The agent constructs and executes `readwise login-with-token <token>`.
3. The complete command, including the token, is retained in shell history, process metadata, terminal output, command-audit logs, or the agent transcript.
4. An attacker or unauthorized operator gains access to one of those records while the token remains valid.
5. The attacker extracts the token and uses it to authenticate to Readwise.
6. The attacker accesses or changes Readwise and Reader data to the extent allowed by the token and the associated CLI/API operations.

### Impact Assessment

Token disclosure could permit unauthorized access to the user's private Readwise highlights and Reader documents. Depending on the token's effective permissions, an attacker may be able to search and r
...[truncated 223 chars]
Remediation
View remediation

Remediation Suggestions

  • Use a CLI-supported interactive prompt, standard-input mechanism, operating-system keychain, or protected credential file instead of placing the token in command-line arguments.
  • Do not include the token in agent-visible command text, transcripts, diagnostic output, or examples.
  • If environment-based authentication is supported, source the token from a protected secret manager rather than entering it directly into an interactive shell; ensure logs do not print the environment.
  • Restrict any credential file to the owning user and avoid storing it in the project directory or version control.
  • Disable or suppress shell history for the authentication operation when no safer input method is available.
  • Document where the CLI stores the authenticated credential and require appropriate file permissions.
  • Advise users to revoke and rotate any token that may have appeared in command history, process logs, or agent transcripts.
  • Prefer narrowly scoped and short-lived credentials if Readwise provides those options.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Requesting the user's Readwise access token is a real credential-access concern because the token likely grants broad API access to private reading history, highlights, notes, and account content. The surrounding context makes this more dangerous, not less, because the skill is specifically designed to operate on sensitive personal data and immediately uses the secret in a command that may expose it to logs or process inspection.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

npm install -g @readwise/cli

text

If not authenticated, ask the user for their Readwise access token (they can get one at https://readwise.io/access_token), then run:
```bash
readwise login-with-token <token>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to ask the user for a long-lived Readwise access token and pass it on the command line, but provides no warning about secret handling, scope, storage, redaction, or safer alternatives. In an agent setting, this creates unnecessary credential exposure risk through chat logs, shell history, process listings, or downstream tooling that may capture arguments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents multiple state-changing operations such as moving documents, bulk editing metadata, creating/deleting highlights, adding/removing tags, and exporting data without requiring confirmation or warning the operator that these actions modify the user's account. In an autonomous or semi-autonomous agent workflow, this increases the chance of accidental destructive changes, privacy-impacting exports, or unintended organization changes at scale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.