notion-meeting-intelligence
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to connect to an external MCP endpoint at
https://mcp.notion.com/mcp. This is an official domain for Notion, which is a well-known technology service. - [COMMAND_EXECUTION]: The workflow includes configuration commands for the
codexCLI to add the Notion MCP, enable remote client features, and perform OAuth login. These are legitimate setup steps for the skill's environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from Notion documents via
Notion:notion-fetchto assist in drafting agendas. This creates a potential surface for indirect prompt injection if the retrieved documents contain malicious instructions. The instructions do not specify explicit boundary markers or sanitization for this external content. - Ingestion points: Notion pages retrieved via
Notion:notion-searchandNotion:notion-fetch(SKILL.md) - Boundary markers: Absent
- Capability inventory: Page creation and updates via
Notion:notion-create-pagesandNotion:notion-update-page(SKILL.md) - Sanitization: Absent
Audit Metadata