knowledge-capture
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest information from conversation context and save it to external documentation. This creates a surface for indirect prompt injection where instructions embedded in the chat data could influence the agent's behavior during the capture process.
- Ingestion points: Discussion context, chat discussions, and problem-solving sessions (SKILL.md).
- Boundary markers: The instructions do not specify any delimiters or safety markers to isolate user-provided text from the agent's instructions.
- Capability inventory: Creating pages, updating databases, and modifying navigation links via the Notion MCP.
- Sanitization: There are no instructions for sanitizing or validating the content extracted from the conversation before it is saved to Notion.
- [NO_CODE]: The skill consists entirely of markdown instructions and YAML metadata without any accompanying scripts, executables, or package dependencies.
Audit Metadata