notion-knowledge-capture
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted conversation context to generate documentation, which creates a potential surface for indirect prompt injection. If a source conversation contains hidden instructions, the agent might inadvertently follow them while performing Notion operations.
- Ingestion points: Conversation context, chat discussions, and problem-solving logs as defined in
SKILL.mdand demonstrated in theexamples/directory. - Boundary markers: The instructions in
SKILL.mdlack explicit delimiters or specific warnings to the model to ignore embedded instructions within the captured content. - Capability inventory: The skill utilizes
Notion:notion-search,Notion:notion-fetch,Notion:notion-create-pages, andNotion:notion-update-pageto interact with the user's workspace. - Sanitization: There is no evidence of sanitization or validation of the extracted information before it is interpolated into the prompts for Notion page creation.
Audit Metadata