notion-spec-to-implementation

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, specifically Notion specification pages.
  • Ingestion points: The skill uses Notion:notion-fetch (referenced in SKILL.md and reference/spec-parsing.md) to read the full content of pages retrieved via Notion:notion-search.
  • Boundary markers: The provided instructions and templates (e.g., reference/standard-implementation-plan.md) lack explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded within the fetched specification text.
  • Capability inventory: The skill possesses write capabilities through Notion:notion-create-pages and Notion:notion-update-page. An attacker could embed instructions in a specification document to influence the creation of malicious tasks or the modification of other Notion data.
  • Sanitization: There is no evidence of content sanitization or validation of the requirements extracted from the Notion pages before they are used to populate implementation plans and task databases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:55 AM
Security Audit — agent-trust-hub — notion-spec-to-implementation