notion-meeting-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from external Notion pages, which establishes a potential attack surface for indirect prompt injection. * Ingestion points: The skill uses the Notion:notion-fetch tool to ingest content from arbitrary Notion pages identified during the search phase. * Boundary markers: The instructions do not specify clear delimiters or provide the agent with explicit directives to ignore instructions embedded within the retrieved Notion content. * Capability inventory: The skill has the ability to write back to the workspace using the Notion:notion-create-pages and Notion:notion-create-comment tools. * Sanitization: There is no evidence of sanitization or validation of the fetched Notion content before it is processed by the agent.
- [NO_CODE]: The skill is implemented entirely through Markdown-based instructions and reference templates, containing no custom scripts, binaries, or executable code.
Audit Metadata