Back to skill

Security audit

Notion 技能基础版

Security checks across malware telemetry and agentic risk

Overview

This Notion skill is mostly purpose-aligned, but it needs review because it can modify Notion content while giving misleading privacy and scope guidance.

Review this before installing. Use it only with a Notion integration limited to the specific pages and databases you intend to automate, do not rely on the claim that data never leaves your machine, and require explicit confirmation before writes, profile switches, or schema-related changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documentation is internally inconsistent: it states the FREE version does not support multi-profile management, yet instructs users to switch between `personal` and `work` profiles via `NOTION_PROFILE`. This can cause agents or users to operate against the wrong workspace or credential context, increasing the chance of unintended data access or modification across accounts.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The claim that all data remains local and is never uploaded to the cloud directly conflicts with the skill's stated use of the Notion API and external network access. This is dangerous because it can mislead users into sharing sensitive content under false privacy assumptions, resulting in unintended transmission of workspace data to third-party services.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger condition is broad and ambiguous, describing general data analysis and reporting needs rather than precise conditions for invoking a skill that can read and modify Notion resources. In an agentic environment, vague routing criteria can cause the skill to be invoked for unrelated prompts, leading to unnecessary credential use, unintended external API calls, or accidental content changes.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill presents capabilities without an upfront warning that it can create, update, append to, and potentially alter Notion pages and databases. This increases the risk that users or orchestrating agents treat it as informational only, when in fact it has write-side effects that may damage content or schemas if invoked inadvertently.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.