Notion Workflows

Security checks across malware telemetry and agentic risk

Overview

This Notion automation skill is coherent and not malicious, but it can view, edit, and export content from the Notion pages or databases you choose to use with it.

Install only if you are comfortable letting the agent operate inside your Notion workspace through your browser session. Keep requests scoped to specific pages or databases, review intended edits before allowing them, and avoid exporting or summarizing sensitive workspace content unless that is the goal.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly references exporting Notion content to PDF/snapshots and scraping database data to CSV, but provides no warning, consent boundary, or privacy guidance for handling potentially sensitive workspace information. In an automation context, this increases the risk of unintended data exfiltration, over-collection, or disclosure of private documents and database contents.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal