notion

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the os.shell.run tool to execute curl commands for API operations (PATCH, DELETE) not natively supported by the agent's standard HTTP tool. It also uses the open command to launch the user's browser for Notion configuration tasks.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing data from external sources.
  • Ingestion points: Untrusted data is ingested from Notion via os.http.request and curl at endpoints such as /v1/pages/{id}, /v1/blocks/{id}/children, and /v1/data_sources/{id}/query.
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious commands embedded within Notion content.
  • Capability inventory: The agent has the ability to execute shell commands (curl, open), perform network requests to the Notion API, and write to local configuration files (~/.atomic-agent/.env).
  • Sanitization: No sanitization, filtering, or escaping logic is prescribed for the content retrieved from the external API before it is processed by the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — notion