Back to skill

Security audit

Getnote Daily Sync

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Get笔记-to-Notion daily sync that uses sensitive note data, but its access and Notion writes match its stated purpose.

Install only if you are comfortable copying today's Get笔记 content into the selected Notion database. Use a Notion integration limited to the intended database, verify the database ID, protect the API tokens, and enable the Cron schedule only if daily automatic syncing is desired.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill will send potentially sensitive note content, recordings, meeting summaries, and todos to external services and create new records in Notion, but the description does not clearly warn users about this data transfer and write action. This can lead to unintentional disclosure of confidential information or unintended modification of a workspace if users trigger the skill without understanding its effects.

Static analysis

No suspicious patterns detected.