notion-knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted conversation context to generate documentation, which creates a potential surface for indirect prompt injection. If a source conversation contains hidden instructions, the agent might inadvertently follow them while performing Notion operations.
  • Ingestion points: Conversation context, chat discussions, and problem-solving logs as defined in SKILL.md and demonstrated in the examples/ directory.
  • Boundary markers: The instructions in SKILL.md lack explicit delimiters or specific warnings to the model to ignore embedded instructions within the captured content.
  • Capability inventory: The skill utilizes Notion:notion-search, Notion:notion-fetch, Notion:notion-create-pages, and Notion:notion-update-page to interact with the user's workspace.
  • Sanitization: There is no evidence of sanitization or validation of the extracted information before it is interpolated into the prompts for Notion page creation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:31 PM
Security Audit — agent-trust-hub — notion-knowledge-capture