spec-to-implementation
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external specification documents from Notion which could contain malicious instructions designed to hijack the agent's behavior.
- Ingestion points: The skill reads specification pages and documents from Notion as described in the workflow in SKILL.md.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched content as untrusted data rather than instructions.
- Capability inventory: The agent uses tools to search Notion, read page content, create new implementation plan pages, and create items in task databases.
- Sanitization: The instructions do not include any steps for the agent to sanitize, validate, or filter the content of the specifications before processing them.
Audit Metadata