custom-blocks
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to locate and follow instructions from an external file:
node_modules/@notionhq/apps/skills/custom-blocks/SKILL.md.\n - Ingestion points: The agent is instructed to read the content of a specific file within the project's dependencies.\n
- Boundary markers: The skill lacks delimiters or specific instructions to treat the external file's content as untrusted data, instead explicitly telling the agent to "Follow the instructions in that file."\n
- Capability inventory: While this skill does not directly invoke tools, it delegates the agent's behavior to external content that could leverage the agent's broader capabilities if compromised.\n
- Sanitization: No sanitization, validation, or integrity checks are performed on the content of the referenced file before processing.
Audit Metadata