notion-opportunity-database
Pass
Audited by Gen Agent Trust Hub on May 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it processes untrusted data from a Notion database without using protective delimiters or sanitization. This data is then passed to other skills, potentially influencing their behavior.
- Ingestion points: Notion database pages (SKILL.md).
- Boundary markers: None used.
- Capability inventory: Notion MCP tools (read/write), job-application-operator skill.
- Sanitization: None specified.
- [COMMAND_EXECUTION]: The skill instructs the agent to create and run local scripts (Category 10). This occurs as a recommended workaround for MCP tool limitations, where the agent is prompted to use the official Notion API via a local script for database queries.
Audit Metadata