Back to skill

Security audit

Korta Notion

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Notion API helper, with the main caution that its setup stores a Notion token in a local plaintext file.

Before installing, create a minimally scoped Notion integration, share only the pages or databases it needs, and store the token with owner-only permissions or in a secret manager rather than leaving it in a broadly readable plaintext file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Notion API Token Stored Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–16
Vulnerability Type: Plaintext sensitive credential with unspecified access permissions
Risk Level: Medium

Vulnerable Code:

bash
mkdir -p ~/.config/notion
echo "ntn_your_key_here" > ~/.config/notion/api_key

Technical Analysis

The documented setup stores the Notion bearer token in a plaintext file without explicitly restricting permissions on either the configuration directory or the token file. Their resulting permissions depend on the user's current umask and any preexisting directory permissions.

If those permissions permit access by other local users or processes, the token can be recovered and submitted directly in the Authorization: Bearer header documented elsewhere in the skill. Although storing a local credential is necessary for this integration, failing to enforce least-privilege permissions creates avoidable credential-exposure risk.

Attack Path

  1. A user follows the setup instructions and writes a valid integration token to ~/.config/notion/api_key.
  2. The user's umask or existing directory permissions result in the directory or file being readable by another local account or compromised process.
  3. The attacker enumerates user configuration files and reads the token.
  4. The attacker sends requests to https://api.notion.com with the stolen token as a bearer credential.
  5. Notion authorizes actions permitted by the integration against pages and data sources shared with it.

This path requires local read access to the credential file or execution in another context capable of reading files belonging to the user.

Impact Assessment

A successful attacker obtains the effective privileges granted to the Notion integration. Depending on its configured capabilities and the resources shared with it, this may permit unauthorized reading, searching, creation, or modification of Notion pages, data sources, pro ...[truncated 192 chars]

Remediation
View remediation

Remediation Suggestions

Enforce owner-only permissions when creating both the directory and credential file:

bash
install -d -m 700 ~/.config/notion
install -m 600 /dev/null ~/.config/notion/api_key
printf '%s\n' "ntn_your_key_here" > ~/.config/notion/api_key
chmod 600 ~/.config/notion/api_key

Prefer prompting without terminal echo rather than placing the real token directly in a command that may be retained in shell history:

bash
install -d -m 700 ~/.config/notion
umask 077
read -rsp "Notion API token: " NOTION_KEY
printf '\n'
printf '%s\n' "$NOTION_KEY" > ~/.config/notion/api_key
unset NOTION_KEY

Where available, use an operating-system credential store or dedicated secret manager instead of a plaintext file. Grant the Notion integration only the capabilities and page access required for its intended tasks, rotate any token suspected of exposure, and avoid logging or printing bearer credentials.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill instructs users to persist a long-lived Notion API key in plaintext at ~/.config/notion/api_key. Plaintext credential storage increases the risk of local disclosure through other tools, backups, misconfigured permissions, shell history mistakes, or malware running as the same user, which could enable unauthorized access to shared Notion content.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Setup

  1. Create an integration at https://notion.so/my-integrations
  2. Copy the API key (starts with ntn_ or secret_)
  3. Store it:
bash

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

Static analysis

No suspicious patterns detected.