notion-automation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines several automation workflows that ingest data from external, potentially untrusted sources, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Data is ingested from Typeform/Google Form submissions, Slack message content, GitHub issue labels/titles, and Google Calendar event descriptions (SKILL.md).
  • Boundary markers: The workflows use standard string interpolation syntax (e.g., '{message}', '{original_message}', '{issue.title}') to map external data into database properties and notification messages. This provides no inherent protection if the source data contains malicious instructions targeting the agent processing the workflow.
  • Capability inventory: The skill facilitates broad capabilities including writing to Notion databases, creating Slack channels, sending emails, and creating calendar events across integrated services.
  • Sanitization: The provided templates and logic do not include specific instructions or steps for sanitizing, filtering, or validating the content retrieved from external APIs before it is used in downstream actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:53 PM
Security Audit — agent-trust-hub — notion-automation