research-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content fetched from external Notion pages, which represents a potential attack surface where data could contain instructions meant to influence agent behavior.
- Ingestion points: Fetches and reads full page content from the Notion workspace as described in the Research Workflow (SKILL.md).
- Boundary markers: The instructions lack explicit boundary markers or directives to treat fetched page content as untrusted data.
- Capability inventory: The skill instructions utilize Notion search, page reading, and page creation/writing capabilities (SKILL.md).
- Sanitization: No input validation or sanitization of the retrieved page content is specified before the agent synthesizes findings or writes output.
Audit Metadata