T09 · Insecure Skill Coding Practices
- Location
scripts/notion-write-idea.py:30- Finding
Notion API Token Exposed Through Process Command-Line Arguments
- Content
View full analysis
` in its process arguments. 4. A local attacker or monitoring process observes the command line while `curl` is active. 5. The attacker extracts the bearer token. 6. The attacker submits requests directly to the Notion API using the stolen token. ### Impact Assessment An attacker who obtains the token can act with the full authority of the associated Notion integration. Depending on which resources were shared with that integration, this may permit reading, creating, or modifying Notion pages and databases. It does n ...[truncated 88 chars]- Remediation
View remediation
