notcrawl
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from Notion pages and databases stored in the local cache (
~/.notcrawl/pagesand~/.notcrawl/notcrawl.db). Because this content is externally sourced and can be modified by third parties sharing a Notion workspace, it represents an attack surface where malicious instructions could be embedded to influence the agent's behavior. - Ingestion points:
~/.notcrawl/pages(Markdown files) and~/.notcrawl/notcrawl.db(SQLite database). - Boundary markers: None specified in the instructions to prevent the agent from following instructions found within the data.
- Capability inventory: Shell execution of the
notcrawlCLI tool, includingsearch,sql, andsynccommands. - Sanitization: No explicit sanitization of ingested content is mentioned, although the SQL interface is restricted to read-only access.
- [COMMAND_EXECUTION]: The skill relies on executing the
notcrawlCLI tool to perform search and synchronization tasks. The agent is instructed to run various subcommands that interact with the local filesystem and the Notion API, granting the agent the capability to perform shell-level operations.
Audit Metadata