notion
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to read and process content from Notion pages and databases, creating a surface for potential indirect prompt injection attacks where instructions embedded in the data could influence agent behavior.
- Ingestion points: Data is ingested from the Notion API via endpoints such as
v1/blocks/{page_id}/childrenandv1/data_sources/{data_source_id}/query. - Boundary markers: The skill documentation does not define specific boundary markers or instructions for the agent to ignore potentially malicious content within the fetched data.
- Capability inventory: The skill uses
curlto perform network operations, allowing for both reading from and writing to the Notion workspace. - Sanitization: No evidence of data sanitization, filtering, or validation is present in the skill instructions.
Audit Metadata