Notion

Security checks across malware telemetry and agentic risk

Overview

This Notion skill is a small declarative wrapper for Notion API workflows, with disclosed credential use and no hidden executable behavior.

Install only a trusted Notion CLI, use a dedicated Notion integration, share it only with the specific pages or databases needed, treat NOTION_API_KEY as a secret, and review any write or schema changes before allowing the agent to apply them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README tells users to export a Notion Internal Integration Token but does not clearly warn that the token is a sensitive credential that grants API access to any pages and databases shared with the integration. In an agent skill context, users may paste or expose environment setup details into logs, shells, or automation environments, increasing the chance of credential leakage and unauthorized access to workspace content.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal