notcrawl

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from Notion pages and databases stored in the local cache (~/.notcrawl/pages and ~/.notcrawl/notcrawl.db). Because this content is externally sourced and can be modified by third parties sharing a Notion workspace, it represents an attack surface where malicious instructions could be embedded to influence the agent's behavior.
  • Ingestion points: ~/.notcrawl/pages (Markdown files) and ~/.notcrawl/notcrawl.db (SQLite database).
  • Boundary markers: None specified in the instructions to prevent the agent from following instructions found within the data.
  • Capability inventory: Shell execution of the notcrawl CLI tool, including search, sql, and sync commands.
  • Sanitization: No explicit sanitization of ingested content is mentioned, although the SQL interface is restricted to read-only access.
  • [COMMAND_EXECUTION]: The skill relies on executing the notcrawl CLI tool to perform search and synchronization tasks. The agent is instructed to run various subcommands that interact with the local filesystem and the Notion API, granting the agent the capability to perform shell-level operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — notcrawl