notion-automation
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of documentation and configuration examples for Notion automation, focusing on legitimate data synchronization and workflow triggers across common office platforms.\n- [PROMPT_INJECTION]: The skill defines workflows that ingest untrusted data from external sources (e.g., Slack messages, form submissions, and GitHub issues), which presents an attack surface for indirect prompt injection. This is a characteristic of the skill's intended automation functionality.\n
- Ingestion points: External content from forms, Slack, and GitHub issues defined in SKILL.md.\n
- Boundary markers: Absent in the workflow configuration examples.\n
- Capability inventory: Capabilities include writing to Notion databases, sending Slack messages, and generating emails.\n
- Sanitization: No sanitization logic is provided in the templates to handle potentially malicious instructions within the ingested data.
Audit Metadata