Back to skill

Security audit

Notion API 2026 01 15

Security checks across malware telemetry and agentic risk

Overview

This skill is a Notion API instruction helper with disclosed Notion-only API access and no hidden execution, but users should be careful with destructive examples and stored API tokens.

Install this only if you want an agent to help operate Notion through your own integration token. Share the Notion integration only with pages or databases it needs, protect ~/.config/notion/api_key, and require explicit confirmation before moving, locking, updating, or erasing page content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents an operation that applies a template with `erase_content: true`, which can irreversibly wipe an existing page's contents, but it does not present a prominent warning, confirmation step, or safer alternative. In an agent-skill context, users or downstream agents may copy this example directly and cause accidental data loss in a live Notion workspace.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.