notion-knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted conversational data and notes to create or update pages in Notion.
  • Ingestion points: Conversational history, notes, and user-provided context (described in Step 3 of the Workflow).
  • Boundary markers: The instructions lack specific delimiters or warnings to ignore embedded instructions within the source text, which could lead the agent to follow malicious commands hidden in the captured content.
  • Capability inventory: The skill uses 'Notion:notion-create-pages' and 'Notion:notion-update-page' which allow it to modify remote database content based on processed input.
  • Sanitization: There is no evidence of input validation or sanitization to ensure that data extracted from conversations does not contain malicious payloads meant to influence future agent interactions with those Notion pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:25 PM
Security Audit — agent-trust-hub — notion-knowledge-capture