T08 · Insecure Dependencies
- Location
README.md:50- Finding
Unpinned Package Execution in Recommended Installation Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Notion API helper, but it can read, create, update, and archive any Notion content shared with its integration.
Install only from a source you trust, prefer a pinned installer version where possible, keep the Notion API key secret, and share only the specific Notion pages or databases the agent should access. Review the agent's plan before create, update, append, or delete-block operations, especially for bulk edits.
README.md:50Unpinned Package Execution in Recommended Installation Command
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
method=method,
)
try:
with urllib.request.urlopen(req, timeout=30) as resp:
raw = resp.read().decode("utf-8", errors="replace")
return json.loads(raw)
except urllib.error.HTTPError as e:
The README emphasizes that the skill gives agents 'complete control' over Notion workspaces and documents deletion-capable and write-capable operations, but it does not provide a clear warning about destructive actions, scope of access, or the need to limit integration permissions. In an agent context, this increases the chance of accidental mass edits, archival, or data corruption by users who may not appreciate the operational risk.
The README instructs users to run npx clawhub@latest install notion-pro, which fetches and executes the latest package version at install time without pinning to a known-good release. This creates a supply-chain risk: a compromised upstream package or malicious new release could execute arbitrary code on the user's system during installation.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
The credential setup section tells users to place the Notion API key in an environment variable or config file but does not warn about the sensitivity of that token or the risk of accidental disclosure through shell history, logs, screenshots, shared configs, or repository commits. Since the token grants workspace API access, exposure could allow unauthorized reading or modification of shared Notion content.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
--filter '{"property": "Status", "select": {"equals": "Active"}}' \
--all
# Create a database entry
python3 scripts/notion_api.py create-page \
--parent-id "def456" \
--parent-type database \
The Chinese installation instructions repeat the same unpinned npx clawhub@latest command, carrying the same supply-chain execution risk. Because npx can download and run remote code immediately, users are exposed to arbitrary code execution if the referenced package is ever tampered with or maliciously updated.
The skill documents a destructive delete-block capability without any explicit warning, confirmation requirement, or guidance to verify targets before removal. In an agent-facing skill, this increases the chance of accidental irreversible deletion of user content, especially when the same document strongly encourages automated multi-step execution.
The page update workflow explicitly instructs reading blocks, identifying a range, deleting old blocks one by one, and appending new content, but it lacks any warning about modifying user data or validating scope before execution. In the context of an autonomous agent skill, this is more dangerous because the workflow operationalizes bulk destructive changes and may normalize unsafe write behavior without guardrails.
L003 将当前文件标记为“中文”版本,且整份技能说明均以中文撰写,但文档中没有说明应根据用户语言偏好选择语言输出或交互。按规则,若技能在自然语言层面强制特定语言且无用户选择或明确合规理由,属于语言/locale 策略风险。
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import urllib.request
import urllib.error
NOTION_BASE = "https://api.notion.com/v1"
NOTION_VERSION = "2025-09-03"
MAX_RETRIES = 3
The CLI exposes state-changing operations such as create, update, append, and delete with no confirmation prompt, dry-run mode, or explicit safety gating. In an agentic context, this increases the chance that a mistaken prompt, unsafe automation, or prompt-injection-driven action will modify or archive Notion content immediately and silently.
No suspicious patterns detected.