Back to skill

Security audit

Notion Skill Publish

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Notion API helper, but it can read, create, update, and archive any Notion content shared with its integration.

Install only from a source you trust, prefer a pinned installer version where possible, keep the Notion API key secret, and share only the specific Notion pages or databases the agent should access. Review the agent's plan before create, update, append, or delete-block operations, especially for bulk edits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:50
Finding

Unpinned Package Execution in Recommended Installation Command

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (12)

Tainted flow: 'req' from os.environ.get (line 64, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/notion_api.py (reported line 71)May include surrounding context.

python
method=method,
        )
        try:
            with urllib.request.urlopen(req, timeout=30) as resp:
                raw = resp.read().decode("utf-8", errors="replace")
                return json.loads(raw)
        except urllib.error.HTTPError as e:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README emphasizes that the skill gives agents 'complete control' over Notion workspaces and documents deletion-capable and write-capable operations, but it does not provide a clear warning about destructive actions, scope of access, or the need to limit integration permissions. In an agent context, this increases the chance of accidental mass edits, archival, or data corruption by users who may not appreciate the operational risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub@latest install notion-pro, which fetches and executes the latest package version at install time without pinning to a known-good release. This creates a supply-chain risk: a compromised upstream package or malicious new release could execute arbitrary code on the user's system during installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

Configure

  1. Create a Notion Integration and copy the API key
  2. Set up authentication (choose one):
bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The credential setup section tells users to place the Notion API key in an environment variable or config file but does not warn about the sensitivity of that token or the risk of accidental disclosure through shell history, logs, screenshots, shared configs, or repository commits. Since the token grants workspace API access, exposure could allow unauthorized reading or modification of shared Notion content.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 153)May include surrounding context.

md
--filter '{"property": "Status", "select": {"equals": "Active"}}' \
  --all

# Create a database entry
python3 scripts/notion_api.py create-page \
  --parent-id "def456" \
  --parent-type database \

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The Chinese installation instructions repeat the same unpinned npx clawhub@latest command, carrying the same supply-chain execution risk. Because npx can download and run remote code immediately, users are exposed to arbitrary code execution if the referenced package is ever tampered with or maliciously updated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents a destructive delete-block capability without any explicit warning, confirmation requirement, or guidance to verify targets before removal. In an agent-facing skill, this increases the chance of accidental irreversible deletion of user content, especially when the same document strongly encourages automated multi-step execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The page update workflow explicitly instructs reading blocks, identifying a range, deleting old blocks one by one, and appending new content, but it lacks any warning about modifying user data or validating scope before execution. In the context of an autonomous agent skill, this is more dangerous because the workflow operationalizes bulk destructive changes and may normalize unsafe write behavior without guardrails.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

L003 将当前文件标记为“中文”版本,且整份技能说明均以中文撰写,但文档中没有说明应根据用户语言偏好选择语言输出或交互。按规则,若技能在自然语言层面强制特定语言且无用户选择或明确合规理由,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/notion_api.py (reported line 17)May include surrounding context.

python
import urllib.request
import urllib.error

NOTION_BASE = "https://api.notion.com/v1"
NOTION_VERSION = "2025-09-03"
MAX_RETRIES = 3

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI exposes state-changing operations such as create, update, append, and delete with no confirmation prompt, dry-run mode, or explicit safety gating. In an agentic context, this increases the chance that a mistaken prompt, unsafe automation, or prompt-injection-driven action will modify or archive Notion content immediately and silently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.