Back to skill

Security audit

Notion 页面管理基础版

Security checks across malware telemetry and agentic risk

Overview

This Notion skill has a coherent purpose, but it requests live workspace read/write access while giving inconsistent privacy, OAuth, and user-control guidance.

Review this carefully before installing. Use it only with a Notion integration limited to the specific pages or databases you intend to manage, avoid broad workspace permissions, and require manual confirmation before any create or update action. Do not rely on the local-only privacy claim unless the publisher clarifies exactly what is sent to Notion, what is cached locally, and how OAuth credentials are stored and revoked.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill claims that FREE-version data is stored locally and not uploaded to the cloud, yet elsewhere it requires OAuth connection to a Notion account and notes that some functions need external API/network access. This creates a misleading security assurance that may cause users to expose workspace data under false assumptions about data flow and trust boundaries.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The documentation presents OAuth credential management as a PRO-only feature, but FREE-version setup and FAQ instruct users to authenticate via OAuth. This inconsistency can mislead users about available security controls and credential-handling behavior, increasing the risk of improper deployment or mistaken trust in edition-specific protections.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger conditions say to use the skill for broad needs like data analysis, reporting, statistics, and visualization, which exceed the stated Notion page/database management scope. Ambiguous invocation boundaries increase the chance an agent will route unrelated or overly sensitive tasks to this skill, leading to unintended data access or misuse of write-capable actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises creation and update capabilities for Notion pages and properties but does not clearly warn users that these are state-changing operations. In an agent-driven context, missing modification warnings and confirmation requirements can lead to accidental overwrites, unwanted content changes, or integrity loss in a user's workspace.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.