build-persona
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's footprint is coherent with its stated purpose: it aggregates Readwise data (highlights, documents, tags) via MCP or CLI, processes it with a Bash+Python script, and emits a local reader_persona.md file used to personalize downstream skills. The data flows are local to the user's environment, with no evident credential handling or external data exfiltration. The design emphasizes parallel data retrieval and controlled parsing, which is appropriate for a data-heavy persona build. Overall risk is low to moderate (benign), assuming trusted sources and proper validation of inputs from MCP/CLI results.
Confidence: 98%
Audit Metadata