notion-research-documentation
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data from external Notion pages via
Notion:notion-fetchto create synthesized reports. While this is the core functionality, instructions embedded in researched Notion documents could theoretically attempt to influence the agent's output. The skill mitigates this risk by providing specific formatting templates and instructional boundaries that prioritize factual extraction over content execution. - [COMMAND_EXECUTION]: The skill instructions include CLI commands for the user to configure the Notion MCP environment (e.g.,
codex mcp add notion). These are legitimate administrative actions required for the skill to function within the supported platform environment and do not involve arbitrary or hidden command execution.
Audit Metadata