Clarity Reader: LLM powered depth-first reading for complex documents
github.com
github.com
- Does the app support embedded LLM-generated links/images (either through HTML or Markdown)?
- Is there any long-term reading history being stored (even locally) that the LLM has access to and that could be included in an exfiltration attack?
- Are there plans to offer external hosting with user accounts, and if so, see above question about image/link support again.
With any LLM tool like this, the answer to "is it vulnerable to prompt injection" is "yes", so the actual question is "how much is the app doing, how bad would prompt injection be?"
In this case, from what I can tell, it's just a self-hosted summary tool, so prompt injection would be limited to a website getting the LLM to generate inaccurate summaries. It doesn't look like the LLM has the ability to insert links/images, but I haven't tested in more detail to make sure. So threat seems minimal?
But I really encourage projects like this to add sections to their README files spelling that out more explicitly. We need to get better as a community at making sure that people understand that prompt injection is a factor that needs to be considered for every single LLM-based project.
When you rely on something else to chunk the knowledge for you, you aren't doing the work.
These tools will be great when they don't miss the details relevant to you, but how are you getting the signal when they do miss details for you?
Same thing with Plato and writing. Writing did not limit memory for those that treated writing as a tool. Writing enabled the throughput of putting stuff into long term memory for many scholars. It also encouraged new ways of work. But a reference or summary could never replace what you put in your head.
We may still ingest knowledge for our own amusement but it won't serve any practical purpose.