Back to skill

Security audit

Notion Integration

Security checks across malware telemetry and agentic risk

Overview

This Notion skill is mostly coherent, but it can modify and archive workspace content without a clear confirmation guard and has broad activation phrases.

Review this before installing if your Notion workspace contains important business or personal data. Use a Notion integration with access only to the pages or databases you actually want automated, and require a manual confirmation before updates, comments, database creation, or archive/delete actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes broad phrases like "Notion integration," "Notion API," "Notion database," and even "Notion token," which can cause the skill to activate on casual discussion rather than a clear user request to perform actions. In this skill, accidental activation is more dangerous because the skill supports reading workspace content and performing write/destructive operations such as creating pages, updating properties, commenting, and archiving pages.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes an archive/delete capability but does not require an explicit warning or confirmation flow before moving pages to trash. Because this integration can affect user data in an external workspace, ambiguous or mistaken invocations could result in unintended data loss or operational disruption even if Notion retains items temporarily.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.