Back to skill

Security audit

memory-to-notion

Security checks for vulnerabilities and agentic risk

Overview

The skill openly archives conversation memories to the user's Notion workspace, but it can process broad chat history and preserve sensitive technical details without mandatory preview or redaction.

Review before installing. Use this only if you are comfortable granting the agent access to conversation content and allowing it to write extracted memories into Notion. Prefer current-session or explicitly selected conversations, review entries before upload, and do not archive secrets, credentials, private keys, session cookies, .env values, or sensitive internal URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:124
Finding

Potential Sensitive Conversation Data Exported to Notion Without Mandatory Redaction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill begins by describing retrieval of past conversation history and storage in Notion, but it does not require an upfront privacy notice or explicit informed consent before accessing and transmitting that data to a third-party service. Because the workflow includes external export and database creation, lack of disclosure materially increases the risk of silent data exfiltration from chat history.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to retrieve past conversation history, derive atomic memory entries, and write them into an external Notion database, including valuable user facts and context. This creates a built-in mechanism for collecting and exporting potentially sensitive personal, project, and operational information outside the original chat boundary.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These instructions direct the agent to fetch recent chats, use search over conversation history, and paginate for comprehensive archival, effectively turning the skill into a chat-history export pipeline. The context makes this especially risky because the workflow normalizes bulk retrieval across multiple conversations, increasing the chance that unrelated sensitive discussions are copied into Notion.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Instructing the agent to preserve code snippets, commands, config values, and URLs verbatim significantly raises the chance of storing API keys, internal endpoints, tokens, credentials, or sensitive infrastructure details in Notion. Verbatim retention is particularly dangerous in a memory-export skill because secrets that appeared transiently in chat become durable, searchable records in an external system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match ordinary requests about reviewing or recording prior discussion, which can invoke a workflow that exports conversation-derived data to Notion without a narrowly scoped confirmation. In this skill, unintended activation is more dangerous because the side effect is external persistence of sensitive memories rather than a local, reversible action.

Content

No source excerpt is available for this finding.