notion-spec-to-implementation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, specifically Notion specification pages.
- Ingestion points: The skill uses
Notion:notion-fetch(referenced inSKILL.mdandreference/spec-parsing.md) to read the full content of pages retrieved viaNotion:notion-search. - Boundary markers: The provided instructions and templates (e.g.,
reference/standard-implementation-plan.md) lack explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded within the fetched specification text. - Capability inventory: The skill possesses write capabilities through
Notion:notion-create-pagesandNotion:notion-update-page. An attacker could embed instructions in a specification document to influence the creation of malicious tasks or the modification of other Notion data. - Sanitization: There is no evidence of content sanitization or validation of the requirements extracted from the Notion pages before they are used to populate implementation plans and task databases.
Audit Metadata