notion-knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the Notion Model Context Protocol (MCP) from https://mcp.notion.com/mcp. This is an official domain for a well-known productivity service.
  • [COMMAND_EXECUTION]: The workflow includes setup steps that require executing CLI commands (codex mcp add, codex mcp login, codex --enable rmcp_client) to configure the environment and authenticate with Notion via OAuth.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it ingests untrusted data from active conversations and existing Notion pages to perform structured extraction and page creation.
  • Ingestion points: Conversational text and notes provided by the user, and existing Notion page content fetched via Notion:notion-fetch.
  • Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions embedded within the source data.
  • Capability inventory: The skill uses Notion:notion-create-pages and Notion:notion-update-page to write data back to the Notion workspace.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the extracted content before writing it to Notion.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 11:14 AM
Security Audit — agent-trust-hub — notion-knowledge-capture