Maverick Notion Mcp

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Notion connector that can read and update Notion content using the user's OAuth-granted Notion access.

Install only if you want an agent to use your authorized Notion workspace access. Confirm the exact Notion page, database, block, comment, or workspace object before any write action, avoid sending unrelated sensitive data through Notion tools, and revoke the Notion OAuth grant when you no longer need it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
The output includes the server's `Instructions:` field (read it) and a JSON Schema for every tool's parameters. Treat this as the authoritative reference for the rest of the session.

**Step 2 - Call any tool from the catalog** using the form `maverick-notion.<tool>`:

```sh
mcporter --config {baseDir}/mcporter.json call maverick-notion.<tool> <arg>=<value> ...
Confidence
91% confidence
Finding
Call any tool

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal