Back to skill

Security audit

Notion Template

Security checks for vulnerabilities and agentic risk

Overview

The main Notion template generator is purpose-aligned, but the package also includes a mismatched local utility script that stores and logs user input without being clearly disclosed in the skill description.

Review before installing. The Notion template script itself appears local and purpose-aligned, but the package also contains an unrelated local data utility. Avoid using the add/list/search/export commands unless you are comfortable with local storage under the skill's data directory, and prefer invoking scripts/notion.sh directly for template generation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill metadata and instructions present the capability as a Notion template generator, but the analyzed behavior reportedly includes unrelated local logging/storage and generic utility functions while lacking the promised Notion-specific functionality. This kind of description-behavior mismatch is dangerous because it can mislead users into invoking a skill under false pretenses, hide undeclared data handling, and reduce a user's ability to assess privacy and operational risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's behavior materially differs from the advertised purpose of a Notion template generator: it implements a generic local logging/data utility with add, search, export, and persistent storage functions. This kind of capability mismatch is dangerous because users may grant trust, install, or execute the skill expecting Notion-related template generation, while it instead collects and stores arbitrary user-supplied data, creating deception and an opportunity for misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The inline description and help text explicitly label the program as a 'Multi-purpose utility tool,' which contradicts the manifest's claim that this is a Notion template generator. Such contradictory identity signals increase the risk of deceptive packaging, reduce informed user consent, and make it easier to hide non-obvious functionality behind an unrelated skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script is a code file, so SQP-3 applies to natural-language strings inside it. The help text and generated content include Chinese labels and descriptions alongside English, which effectively imposes a bilingual/Chinese locale on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The add command writes user input to persistent storage in the user's data directory with only minimal console feedback and no meaningful disclosure of retention, location, or sensitivity expectations. In the context of a skill presented as a Notion template generator, this undisclosed persistence is more suspicious because users would not reasonably expect a local activity/data log unrelated to template generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The heading 'When User Asks for Notion Templates' and the subsequent instruction to run a script do not define specific trigger phrases, boundaries, or exclusion conditions. This is broad enough to overlap with many ordinary requests about Notion and could cause unintended invocation when the user is asking for advice rather than requesting a template generation workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.