notion-research-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by fetching and synthesizing content from external Notion pages without explicit sanitization or boundary markers.
- Ingestion points: Data is ingested through the
Notion:notion-fetchtool as described inSKILL.mdand demonstrated inexamples/technical-investigation.mdandexamples/competitor-analysis.md. - Boundary markers: There are no specific instructions or delimiters mentioned in
SKILL.mdor the reference guides to treat the fetched content as data only or to ignore embedded instructions within those pages. - Capability inventory: The skill has the capability to write back to the workspace using
Notion:notion-create-pages, allowing potentially manipulated content to be saved as official documentation. - Sanitization: No evidence of sanitization or validation of the fetched page content is present in the provided instructions or reference guides.
Audit Metadata