notion-research-documentation

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes legitimate requests to the Notion platform (notion.so) to facilitate searching and retrieving workspace content. These actions are consistent with the skill's primary function and target a well-known service.\n- [INDIRECT_PROMPT_INJECTION]: As the skill ingests content from external Notion pages for synthesis, it possesses an inherent attack surface for indirect prompt injection. However, the risk is minimized as the skill's capabilities are scoped to the Notion environment and do not include high-privilege operations like shell execution or arbitrary network access. The synthesis workflow, while lacking explicit boundary markers, is focused on generating documentation based on user-requested research topics.\n- [DATA_EXFILTRATION]: All data processing and storage occur within the user's Notion workspace. There is no evidence of the skill attempting to transmit sensitive information to external or unauthorized domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 12:25 AM
Security Audit — agent-trust-hub — notion-research-documentation