Back to skill

Security audit

Notion Cli Tool Free

Security checks across malware telemetry and agentic risk

Overview

This Notion command-line skill is mostly coherent, but it grants mutation access to a Notion workspace without clear confirmation safeguards and has a broad trigger condition.

Review before installing. Use a Notion integration with the minimum permissions and share only the databases you want this tool to access. Prefer read/query commands first, and require explicit approval before page updates, archive actions, comments, appends, alias changes, or block deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger condition is broad enough that an agent could invoke this skill in many generic work-assistance scenarios without a strong user request for Notion operations. Because the skill has exec/write capabilities and can modify or delete workspace content, overbroad triggering increases the chance of unintended destructive actions in the user's Notion workspace.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill prominently documents create, update, archive, edit, and delete operations but does not provide an explicit risk warning or safety workflow for destructive changes. In an agent context, this can lead users or autonomous flows to perform irreversible or hard-to-audit modifications to Notion content without realizing the risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.