notion-spec-to-implementation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to search for and ingest arbitrary specification data from Notion pages using the Notion:notion-fetch tool.
  • Ingestion Points: Content is fetched dynamically from specified Notion documents during the workflow execution detailed in SKILL.md and reference/spec-parsing.md.
  • Boundary Markers: There are no explicit boundaries or instruction containment markers configured to isolate processed spec content from the core model instructions.
  • Capability Inventory: The skill is authorized to use Notion:notion-create-pages and Notion:notion-update-page to automatically generate documentation and create tasks within database collections.
  • Sanitization: Content validation or parsing controls are absent, which means structured or free-text descriptions inside incoming documents could potentially influence downstream automated logic if malicious content is introduced into the specification source.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 AM
Security Audit — agent-trust-hub — notion-spec-to-implementation