notion-apps
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides a command to install the
ntnCLI tool by piping a script fromhttps://ntn.devdirectly into the bash shell. This URL serves as the installation source for the tool described in the skill metadata. - [COMMAND_EXECUTION]: The agent is instructed to execute shell commands using the
ntnCLI for tasks such as scaffolding new projects (ntn apps new), enabling experimental features (ntn experiments enable), and verifying the tool version. - [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read and follow the design and implementation guidance contained within a generated
AGENTS.mdfile. \n - Ingestion points:
AGENTS.mdfile located in the generated project root. \n - Boundary markers: None present in the instructions. \n
- Capability inventory: Shell command execution (
ntn), file system access for scaffolding, and Git initialization. \n - Sanitization: No validation or filtering of the file's content is specified.
Recommendations
- HIGH: Downloads and executes remote code from: https://ntn.dev - DO NOT USE without thorough review
Audit Metadata