meeting-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources and existing Notion pages, which is a common surface for indirect prompt injection.
- Ingestion points: Reads content from Notion search results and external research (public info) as defined in Steps 2 and 3 of the workflow.
- Boundary markers: The skill does not define specific boundary markers or instructions to the agent to disregard instructions embedded within the ingested content.
- Capability inventory: The skill uses the agent's ability to search, read, and write pages within the Notion workspace.
- Sanitization: No content sanitization or validation steps are specified for the gathered information before it is formatted into the new documents.
- [NO_CODE]: The skill consists entirely of natural language instructions and structural templates. It does not include any scripts, executable binaries, or package dependencies that could introduce traditional software vulnerabilities.
Audit Metadata