notion-cms
Fail
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The workflow instructions in
SKILL.md(Protocol 2 and Workflow Example) guide the agent to execute a shell command (python3 ...) using values fetched directly from Notion (like the page title) within the--frontmatterargument. If a Notion page title contains shell-sensitive characters (such as backticks, semicolons, or single quotes), it can result in arbitrary command execution on the host environment when the agent runs the conversion command. - [COMMAND_EXECUTION]: The
scripts/json_to_markdown.pyscript takes an--outputargument and usesopen(output_file, 'w')to write the results. If an attacker influences the output path via a crafted page title or database property, this could be used to overwrite sensitive files on the system. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes content from Notion without sanitization or boundary markers.
- Ingestion points: Data enters the system from the Notion API (blocks and properties) via the
mcp_notion_server_APItools. - Boundary markers: None. The agent is not instructed to disregard potential instructions embedded within the Notion block data.
- Capability inventory: The skill has access to shell command execution (
run_command) and file writing capabilities. - Sanitization: The Python conversion script transforms JSON structure to Markdown but does not sanitize or filter the text content for embedded instructions or malicious payloads.
Recommendations
- AI detected serious security threats
Audit Metadata