notion-knowledge-capture

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Indirect Prompt Injection] (SAFE): Surface area detected. 1. Ingestion points: User conversation context and chat history. 2. Boundary markers: None explicitly mentioned in prompt instructions. 3. Capability inventory: Notion:notion-create-pages, Notion:notion-update-page, and Notion:notion-search. 4. Sanitization: None explicitly provided in instructions. This surface is inherent to the primary goal of capturing user notes and is not a malicious pattern.
  • [External Downloads] (SAFE): Setup instructions guide the user to connect to the official Notion MCP server. This is a standard integration step for this skill's functionality.
  • [Command Execution] (SAFE): The skill provides manual setup commands for the user to configure the Notion MCP client. No automated or unauthorized command execution by the agent was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:56 PM