knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest information from conversation context and save it to external documentation. This creates a surface for indirect prompt injection where instructions embedded in the chat data could influence the agent's behavior during the capture process.
  • Ingestion points: Discussion context, chat discussions, and problem-solving sessions (SKILL.md).
  • Boundary markers: The instructions do not specify any delimiters or safety markers to isolate user-provided text from the agent's instructions.
  • Capability inventory: Creating pages, updating databases, and modifying navigation links via the Notion MCP.
  • Sanitization: There are no instructions for sanitizing or validating the content extracted from the conversation before it is saved to Notion.
  • [NO_CODE]: The skill consists entirely of markdown instructions and YAML metadata without any accompanying scripts, executables, or package dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:43 AM
Security Audit — agent-trust-hub — knowledge-capture