notion-research-documentation
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to add a Notion integration from a legitimate remote source (https://mcp.notion.com/mcp).
- [COMMAND_EXECUTION]: Workflow instructions guide the user to execute shell commands for setting up the environment, including configuring local settings and logging into the Notion service.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. Ingestion points: Untrusted data is retrieved from Notion pages using the Notion:notion-fetch tool. Boundary markers: The instructions lack specific delimiters or guidelines to ignore instructions embedded within the fetched content. Capability inventory: The agent can create and modify content in the user's workspace using Notion:notion-create-pages and Notion:notion-update-page tools. Sanitization: There is no evidence of validation or filtering of the content retrieved from Notion before it is processed by the agent.
Audit Metadata