skills/letta-ai/skills/notion/Gen Agent Trust Hub

notion

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to read and process content from Notion pages and databases, creating a surface for potential indirect prompt injection attacks where instructions embedded in the data could influence agent behavior.
  • Ingestion points: Data is ingested from the Notion API via endpoints such as v1/blocks/{page_id}/children and v1/data_sources/{data_source_id}/query.
  • Boundary markers: The skill documentation does not define specific boundary markers or instructions for the agent to ignore potentially malicious content within the fetched data.
  • Capability inventory: The skill uses curl to perform network operations, allowing for both reading from and writing to the Notion workspace.
  • Sanitization: No evidence of data sanitization, filtering, or validation is present in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — notion