notion-api

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external content from Notion workspaces which serves as an ingestion point for untrusted data. 1. Ingestion points: Data is retrieved from Notion pages, blocks, and databases via curl calls to api.notion.com (SKILL.md). 2. Boundary markers: The skill does not provide specific instructions to use delimiters or ignore embedded instructions within the retrieved content. 3. Capability inventory: The skill uses curl for network communication and can modify or delete workspace content through various PATCH, POST, and DELETE endpoints (SKILL.md). 4. Sanitization: The skill lacks explicit sanitization of retrieved data, although it requires user confirmation before executing destructive or bulk operations.
  • [COMMAND_EXECUTION]: The skill utilizes curl and jq to perform REST API calls to interact with Notion workspace data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:59 PM
Security Audit — agent-trust-hub — notion-api