notion-knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it processes untrusted chat conversations to generate and update Notion documentation.
  • Ingestion points: Untrusted conversation context is ingested and processed in SKILL.md (Step 1: Identify content to capture) and used to populate page content.
  • Boundary markers: None. The skill instructions do not define delimiters (e.g., XML tags or backticks) or include "ignore embedded instructions" warnings for the agent when processing the captured text.
  • Capability inventory: The skill uses Notion:notion-create-pages and Notion:notion-update-page (as seen in SKILL.md Step 6 and examples/conversation-to-faq.md) to write content and modify existing page structures in the user's workspace.
  • Sanitization: No content validation, escaping, or filtering is performed on the extracted conversation data before it is written to the remote service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:55 AM
Security Audit — agent-trust-hub — notion-knowledge-capture