notion-knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to ingest and process user conversation history to create structured Notion documentation. While this creates a pathway for untrusted data to reach a connected service, the primary purpose is organizational documentation. Standard review of generated content is recommended.\n
  • Ingestion points: User-provided chat history and notes as referenced in SKILL.md.\n
  • Boundary markers: No specific instructions are provided to the agent regarding markers to separate user data from system instructions.\n
  • Capability inventory: The skill utilizes tools to create and update Notion records.\n
  • Sanitization: Input sanitization steps are not explicitly defined in the skill logic.\n- [Service Integration]: The skill references the official Notion MCP server endpoint for data synchronization. This targets a well-known service provider and follows standard integration practices for this type of agent skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:15 AM
Security Audit — agent-trust-hub — notion-knowledge-capture