skills/openhands/skills/notion/Gen Agent Trust Hub

notion

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION] (LOW): The skill uses curl to transmit data to api.notion.com. While this is the official service endpoint, it is not on the pre-approved whitelist for exfiltration analysis.
  • [PROMPT_INJECTION] (LOW): The skill reads external content from Notion, creating an indirect prompt injection surface. 1. Ingestion points: Data enters the context through api.notion.com/v1/search and block retrieval endpoints. 2. Boundary markers: Absent; there are no instructions to the agent to treat retrieved content as untrusted. 3. Capability inventory: Shell command execution via curl and jq. 4. Sanitization: Absent; data is displayed to the agent context without filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 05:40 PM