Notion 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Notion API guide with expected credential and workspace-access risks, but no evidence of hidden or malicious behavior.

Install only if you want the agent to access Notion through your own integration. Scope the Notion integration to the minimum pages or databases needed, protect the local API key file, avoid committing or sharing the key, and review any create or update command before it changes your workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to store a long-lived Notion API key in a plaintext file under ~/.config/notion/api_key and immediately use it in authenticated API calls, but it provides no warning about local secret exposure or about sending workspace content to a third-party service. This is dangerous because other local users, backup systems, logs, or malware may recover the token, and users may unknowingly transmit sensitive page or database contents to Notion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal