notion-research-documentation

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by fetching and synthesizing content from external Notion pages without explicit sanitization or boundary markers.
  • Ingestion points: Data is ingested through the Notion:notion-fetch tool as described in SKILL.md and demonstrated in examples/technical-investigation.md and examples/competitor-analysis.md.
  • Boundary markers: There are no specific instructions or delimiters mentioned in SKILL.md or the reference guides to treat the fetched content as data only or to ignore embedded instructions within those pages.
  • Capability inventory: The skill has the capability to write back to the workspace using Notion:notion-create-pages, allowing potentially manipulated content to be saved as official documentation.
  • Sanitization: No evidence of sanitization or validation of the fetched page content is present in the provided instructions or reference guides.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:55 AM
Security Audit — agent-trust-hub — notion-research-documentation