notion-knowledge-capture
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it processes untrusted chat conversations to generate and update Notion documentation.
- Ingestion points: Untrusted conversation context is ingested and processed in
SKILL.md(Step 1: Identify content to capture) and used to populate page content. - Boundary markers: None. The skill instructions do not define delimiters (e.g., XML tags or backticks) or include "ignore embedded instructions" warnings for the agent when processing the captured text.
- Capability inventory: The skill uses
Notion:notion-create-pagesandNotion:notion-update-page(as seen inSKILL.mdStep 6 andexamples/conversation-to-faq.md) to write content and modify existing page structures in the user's workspace. - Sanitization: No content validation, escaping, or filtering is performed on the extracted conversation data before it is written to the remote service.
Audit Metadata