Back to skill

Security audit

notion-test

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward Notion API guide, but it tells users to store a long-lived Notion token in a local plaintext file without permission safeguards.

Review before installing if your Notion workspace contains sensitive business or personal data. If you use it, create a narrowly scoped Notion integration, share only the pages or data sources needed, store the token with owner-only permissions or a secret manager, avoid placing real tokens in shell history, and rotate the token if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Notion API Credential Stored Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–17
Vulnerability Type: Insecure credential storage
Risk Level: Medium

Vulnerable Code

bash
mkdir -p ~/.config/notion
echo "ntn_your_key_here" > ~/.config/notion/api_key

Technical Analysis

The setup instructions store a sensitive Notion integration token without explicitly restricting permissions on either the containing directory or the credential file. Under a common 022 umask, the directory may be created with mode 755 and the file with mode 644. In a multi-user environment, this can allow other local users to read the API token.

The instructions also encourage users to place the token directly in a shell command. Depending on the shell configuration, the command containing the token may be retained in shell history, creating an additional plaintext copy of the secret.

Attack Path

  1. A user follows the documented setup instructions and substitutes a real Notion integration token into the echo command.
  2. The token is written to ~/.config/notion/api_key without an explicit restrictive mode and may also remain in shell history.
  3. Another local user or a compromised process running with sufficient filesystem access reads the credential file or shell-history entry.
  4. The attacker submits the stolen token as a bearer credential to https://api.notion.com.
  5. The attacker reads or modifies Notion resources that have been shared with the compromised integration.

Exploitation requires local access to the user's files or another process operating under permissions that permit such access.

Impact Assessment

Successful exploitation exposes the privileges granted to the Notion integration. Depending on its configured capabilities and shared resources, an attacker could search and read sensitive workspace content, create pages or data sources, alter page properties and blocks, or otherwise modify accessible Notion da ...[truncated 218 chars]

Remediation
View remediation

Remediation Suggestions

  • Create the credential directory with owner-only permissions:
    bash
    install -d -m 700 ~/.config/notion
    
  • Collect the token without displaying it or including it in the command line, then create the file under a restrictive umask:
    bash
    read -rsp "Notion API key: " NOTION_KEY
    printf '\n'
    umask 077
    printf '%s\n' "$NOTION_KEY" > ~/.config/notion/api_key
    unset NOTION_KEY
    
  • Explicitly enforce mode 600 on the resulting file:
    bash
    chmod 600 ~/.config/notion/api_key
    
  • Prefer an operating-system credential store or managed secret manager when available.
  • Document that users who previously followed the insecure command should remove any shell-history entry containing the token and rotate the token if unauthorized disclosure may have occurred.
  • Grant the integration only the minimum capabilities and page access needed for its intended tasks.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The skill instructs users to persist a long-lived API token in plaintext under ~/.config/notion/api_key without mentioning restrictive file permissions or safer secret storage. On multi-user systems, backups, endpoint telemetry, or accidental file exposure, this can lead to credential theft and unauthorized access to the user's Notion workspace.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Setup

  1. Create an integration at https://notion.so/my-integrations
  2. Copy the API key (starts with ntn_ or secret_)
  3. Store it:
bash

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

All requests need:

bash
NOTION_KEY=$(cat ~/.config/notion/api_key)
curl -X GET "https://api.notion.com/v1/..." \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2025-09-03" \
  -H "Content-Type: application/json"

Static analysis

No suspicious patterns detected.