Back to skill

Security audit

Notion技能

Security checks for vulnerabilities and agentic risk

Overview

This Notion skill is not plainly malicious, but it asks for broad local file and command powers while also allowing Notion content changes and deletes without clear safeguards.

Install only if you are comfortable giving the agent access to a Notion integration that can change or delete shared Notion content, and avoid enabling broad local file or command execution unless the runtime enforces its own sandbox, path limits, and confirmation prompts. Use a minimally scoped Notion token shared only with the pages/databases needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:26
Finding

Excessive Local File and Command-Execution Capabilities

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:26-29 (capability declaration), corroborated by SKILL.md:323-327 and SKILL.md:360-363
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: Medium

Vulnerable Code Snippet

yaml
tools:
- read
- exec
- write

Technical Analysis

The skill is presented as an integration for performing page and database operations through the official Notion REST API. However, it requests unrestricted local file-reading, file-writing, and command-execution tools. The document later describes generic file processing and system-command execution, but it does not define enforceable path restrictions, a command allowlist, argument validation, mutation confirmation, or sandbox boundaries.

Notion API operations do not inherently require arbitrary local command execution or unrestricted filesystem access. Granting these capabilities therefore expands the skill's authority beyond its primary task and violates the principle of least privilege.

This finding does not establish that the skill contains an embedded malicious payload. Rather, it identifies an excessive-permission condition that could be exploited through malicious or misleading user input, untrusted Notion content, or erroneous agent behavior.

Attack Path

  1. The Agent loads the skill and grants the declared read, write, and exec capabilities.
  2. An attacker supplies a request, or places content in a Notion resource, that directs the Agent to inspect a local file or execute a system command.
  3. Because the skill provides no enforceable command or path restrictions, the Agent may interpret the request as permitted generic file processing or command execution.
  4. The Agent invokes read, write, or exec with attacker-influenced paths or arguments.
  5. The operation runs with the permissions of the Agent process, potentially exposing or modifying accessible lo ...[truncated 751 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, and write from the tool declaration unless each capability is necessary for a documented Notion workflow.
  2. Replace generic execution capabilities with a dedicated Notion API client exposing only required operations and HTTPS endpoints.
  3. If local file import or export is required, restrict access to a dedicated workspace directory and reject absolute paths, parent-directory traversal, symbolic-link escapes, and sensitive-file locations.
  4. If command execution is unavoidable, implement a strict executable-and-subcommand allowlist. Pass arguments as structured arrays rather than interpolated shell strings, and prohibit shell metacharacters and attacker-controlled environment variables.
  5. Require explicit user confirmation before destructive API operations, local writes, deletions, or command execution.
  6. Run the skill in a sandbox with a read-only filesystem by default, no unnecessary environment secrets, restricted network egress, and a non-privileged operating-system account.
  7. Use a minimally scoped Notion integration token and expose it only to the dedicated API client rather than generic commands.
  8. Add security tests verifying that untrusted user input and Notion content cannot trigger arbitrary path access or command execution.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description states '支持中文交互,无需复杂配置即开即用', which presents Chinese interaction as a built-in behavior, and the surrounding document is primarily framed in Chinese without indicating user choice. Under the language/locale policy, skills should not impose a specific language unless users can opt in or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises full CRUD operations, including delete, against Notion pages and databases without prominently warning that these actions can permanently modify or remove workspace content. In an agent setting, omission of destructive-action warnings increases the likelihood of accidental data loss from ambiguous prompts or over-broad automation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation gives conflicting capability boundaries: it says file uploads are not directly supported, yet later describes file reading, writing, and output-file handling. This ambiguity can mislead an agent or user into granting broader filesystem behavior than intended, increasing the chance of unsafe file access or data handling assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims command execution is sandboxed and limited to whitelisted commands, but provides no implementation or enforceable policy showing those protections exist. Unsupported safety claims can cause operators or downstream agents to trust exec functionality too much, creating risk of arbitrary command execution or privilege misuse if the environment is less restricted than described.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.