workspace-documentation

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process conversation history, which is an external and untrusted data source. This ingestion creates a surface for potential indirect prompt injection.\n
  • Ingestion points: SKILL.md (Workflow Step 1) and evaluations/conversation-to-wiki.json specify identifying key concepts, decisions, and procedures from the 'conversation context'.\n
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore embedded instructions' warnings for the agent to follow when processing the chat history.\n
  • Capability inventory: The skill utilizes powerful tools to modify the workspace, including Notion:notion-search, Notion:notion-create-pages, and Notion:notion-update-page.\n
  • Sanitization: The instructions do not implement validation or sanitization protocols for the extracted content before it is committed to the Notion workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:00 PM
Security Audit — agent-trust-hub — workspace-documentation