connections

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The instructions direct the agent to load and follow content from an external file (node_modules/@notionhq/apps/skills/connections/SKILL.md). This establishes a surface where the agent's behavior is determined by data fetched from the project's dependency directory.\n
  • Ingestion points: node_modules/@notionhq/apps/skills/connections/SKILL.md (via instructions in SKILL.md)\n
  • Boundary markers: None present; the agent is instructed to follow the file's content directly.\n
  • Capability inventory: The skill is intended to configure and use provider connections and triggers.\n
  • Sanitization: No validation or sanitization of the external content is performed.\n- [EXTERNAL_DOWNLOADS]: The skill mentions the installation of project dependencies, specifically referencing the @notionhq/apps package, which is a vendor-owned resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:37 AM
Security Audit — agent-trust-hub — connections