notion-research-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to fetch and synthesize data from external Notion pages and potentially third-party integrations like Slack, Google Drive, GitHub, and Jira. This creates a surface area for indirect prompt injection where malicious instructions inside those external documents could theoretically influence the agent's behavior during synthesis.
- Ingestion points: The skill uses
Notion:notion-fetchandNotion:notion-searchto pull content into the agent's context. - Boundary markers: The templates provided for reports (e.g., in
reference/research-summary-template.md) do not explicitly define delimiters or instructions to ignore embedded commands in the source text. - Capability inventory: The agent has the capability to write new pages to the workspace using
Notion:notion-create-pages. - Sanitization: No explicit sanitization or filtering of retrieved content is mandated in the provided workflow.
- [NO_CODE]: The skill consists entirely of Markdown-based instructions, reference documentation, and JSON-based evaluation scenarios. It does not include any executable scripts (e.g., Python or Node.js), which eliminates risks associated with remote code execution or traditional shell-based privilege escalation.
Audit Metadata