custom-blocks

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to locate and follow instructions from an external file: node_modules/@notionhq/apps/skills/custom-blocks/SKILL.md.\n
  • Ingestion points: The agent is instructed to read the content of a specific file within the project's dependencies.\n
  • Boundary markers: The skill lacks delimiters or specific instructions to treat the external file's content as untrusted data, instead explicitly telling the agent to "Follow the instructions in that file."\n
  • Capability inventory: While this skill does not directly invoke tools, it delegates the agent's behavior to external content that could leverage the agent's broader capabilities if compromised.\n
  • Sanitization: No sanitization, validation, or integrity checks are performed on the content of the referenced file before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:37 AM
Security Audit — agent-trust-hub — custom-blocks