skills/openhands/extensions/notion/Gen Agent Trust Hub

notion

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl and jq in Bash, and Invoke-RestMethod and ConvertTo-Json in PowerShell, to communicate with the Notion REST API as documented in SKILL.md and references/windows.md.- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes content from Notion pages and databases, which could contain instructions intended to influence the agent's behavior.
  • Ingestion points: Data retrieved from Notion search results and block/page queries (SKILL.md).
  • Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore instructions found within retrieved Notion content.
  • Capability inventory: The agent can execute shell commands (curl) to interact with the API.
  • Sanitization: No validation or sanitization of content fetched from the Notion API is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — notion