workspace-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process conversation history, which is an external and untrusted data source. This ingestion creates a surface for potential indirect prompt injection.\n
- Ingestion points:
SKILL.md(Workflow Step 1) andevaluations/conversation-to-wiki.jsonspecify identifying key concepts, decisions, and procedures from the 'conversation context'.\n - Boundary markers: The instructions do not define explicit delimiters or 'ignore embedded instructions' warnings for the agent to follow when processing the chat history.\n
- Capability inventory: The skill utilizes powerful tools to modify the workspace, including
Notion:notion-search,Notion:notion-create-pages, andNotion:notion-update-page.\n - Sanitization: The instructions do not implement validation or sanitization protocols for the extracted content before it is committed to the Notion workspace.
Audit Metadata