highlight-graph

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior fits the stated purpose of visualizing Readwise highlights, and data flows are mostly proportional. The main issue is install/execution trust: the required `readwise` fallback CLI is not pinned or clearly tied to the official Readwise distribution, creating supply-chain ambiguity. Privacy exposure is moderate because user highlights are analyzed by subagents and rendered via an HTML page that may load a CDN script, but there is no clear credential harvesting or off-platform exfiltration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:59 PM
Package URL
pkg:socket/skills-sh/readwiseio%2Freadwise-skills%2Fhighlight-graph%2F@7251c29bb3d97f78a1b76cb92658ce05c10369df