T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Notion API Credential Stored Without Restrictive File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–17
Vulnerability Type: Insecure credential storage
Risk Level: MediumVulnerable Code
bash mkdir -p ~/.config/notion echo "ntn_your_key_here" > ~/.config/notion/api_keyTechnical Analysis
The setup instructions store a sensitive Notion integration token without explicitly restricting permissions on either the containing directory or the credential file. Under a common
022umask, the directory may be created with mode755and the file with mode644. In a multi-user environment, this can allow other local users to read the API token.The instructions also encourage users to place the token directly in a shell command. Depending on the shell configuration, the command containing the token may be retained in shell history, creating an additional plaintext copy of the secret.
Attack Path
- A user follows the documented setup instructions and substitutes a real Notion integration token into the
echocommand. - The token is written to
~/.config/notion/api_keywithout an explicit restrictive mode and may also remain in shell history. - Another local user or a compromised process running with sufficient filesystem access reads the credential file or shell-history entry.
- The attacker submits the stolen token as a bearer credential to
https://api.notion.com. - The attacker reads or modifies Notion resources that have been shared with the compromised integration.
Exploitation requires local access to the user's files or another process operating under permissions that permit such access.
Impact Assessment
Successful exploitation exposes the privileges granted to the Notion integration. Depending on its configured capabilities and shared resources, an attacker could search and read sensitive workspace content, create pages or data sources, alter page properties and blocks, or otherwise modify accessible Notion da ...[truncated 218 chars]
- A user follows the documented setup instructions and substitutes a real Notion integration token into the
- Remediation
View remediation
Remediation Suggestions
- Create the credential directory with owner-only permissions:
bash install -d -m 700 ~/.config/notion - Collect the token without displaying it or including it in the command line, then create the file under a restrictive umask:
bash read -rsp "Notion API key: " NOTION_KEY printf '\n' umask 077 printf '%s\n' "$NOTION_KEY" > ~/.config/notion/api_key unset NOTION_KEY - Explicitly enforce mode
600on the resulting file:bash chmod 600 ~/.config/notion/api_key - Prefer an operating-system credential store or managed secret manager when available.
- Document that users who previously followed the insecure command should remove any shell-history entry containing the token and rotate the token if unauthorized disclosure may have occurred.
- Grant the integration only the minimum capabilities and page access needed for its intended tasks.
- Create the credential directory with owner-only permissions:
