T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Notion API Token Stored Without Restrictive File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–16
Vulnerability Type: Plaintext sensitive credential with unspecified access permissions
Risk Level: MediumVulnerable Code:
bash mkdir -p ~/.config/notion echo "ntn_your_key_here" > ~/.config/notion/api_keyTechnical Analysis
The documented setup stores the Notion bearer token in a plaintext file without explicitly restricting permissions on either the configuration directory or the token file. Their resulting permissions depend on the user's current
umaskand any preexisting directory permissions.If those permissions permit access by other local users or processes, the token can be recovered and submitted directly in the
Authorization: Bearerheader documented elsewhere in the skill. Although storing a local credential is necessary for this integration, failing to enforce least-privilege permissions creates avoidable credential-exposure risk.Attack Path
- A user follows the setup instructions and writes a valid integration token to
~/.config/notion/api_key. - The user's
umaskor existing directory permissions result in the directory or file being readable by another local account or compromised process. - The attacker enumerates user configuration files and reads the token.
- The attacker sends requests to
https://api.notion.comwith the stolen token as a bearer credential. - Notion authorizes actions permitted by the integration against pages and data sources shared with it.
This path requires local read access to the credential file or execution in another context capable of reading files belonging to the user.
Impact Assessment
A successful attacker obtains the effective privileges granted to the Notion integration. Depending on its configured capabilities and the resources shared with it, this may permit unauthorized reading, searching, creation, or modification of Notion pages, data sources, pro ...[truncated 192 chars]
- A user follows the setup instructions and writes a valid integration token to
- Remediation
View remediation
Remediation Suggestions
Enforce owner-only permissions when creating both the directory and credential file:
bash install -d -m 700 ~/.config/notion install -m 600 /dev/null ~/.config/notion/api_key printf '%s\n' "ntn_your_key_here" > ~/.config/notion/api_key chmod 600 ~/.config/notion/api_keyPrefer prompting without terminal echo rather than placing the real token directly in a command that may be retained in shell history:
bash install -d -m 700 ~/.config/notion umask 077 read -rsp "Notion API token: " NOTION_KEY printf '\n' printf '%s\n' "$NOTION_KEY" > ~/.config/notion/api_key unset NOTION_KEYWhere available, use an operating-system credential store or dedicated secret manager instead of a plaintext file. Grant the Notion integration only the capabilities and page access required for its intended tasks, rotate any token suspected of exposure, and avoid logging or printing bearer credentials.
