Back to skill

Security audit

Notion

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Notion API helper, but it concentrates broad workspace access through a third-party gateway and includes unsafe credential troubleshooting guidance.

Install only if you trust Maton with the Notion workspace content and operations you will send through its gateway. Use the least-privileged Notion connection possible, avoid giving access to unrelated pages, require explicit confirmation before archive/delete/schema changes, and do not run or share output from 'echo $MATON_API_KEY'; rotate the key if it has already been exposed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:276
Finding

API Credential Exposed Through Troubleshooting Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 276-280
Vulnerability Type: API key disclosure through terminal output
Risk Level: High

Vulnerable Code Snippet:

shell
Troubleshooting
Check API key
echo $MATON_API_KEY

Technical Analysis

The troubleshooting procedure instructs users or agents to print the complete MATON_API_KEY value to standard output. Terminal output may be retained in agent transcripts, continuous-integration logs, shell history recordings, debugging reports, or shared terminal sessions.

The instruction does not mask the credential, validate only its presence, or warn users against publishing the resulting output. Because the API key authenticates requests to Maton's connection-management and Notion gateway services, disclosure can give another party access to the resources associated with the key.

Attack Path

  1. A user or agent encounters an authentication or connection problem.
  2. The troubleshooting instructions are followed and echo $MATON_API_KEY is executed.
  3. The complete credential appears in terminal output.
  4. The output is retained in an agent conversation, CI log, diagnostic report, screen recording, or shared terminal.
  5. An attacker with access to that output extracts the API key.
  6. The attacker submits the key in an Authorization: Bearer header to Maton's gateway or connection-management API.
  7. The attacker accesses or modifies resources permitted by the victim's associated Notion OAuth connection.

Impact Assessment

Successful exploitation can expose the Maton account's connection metadata and grant access to connected Notion resources within the OAuth connection's effective permissions. Depending on those permissions, the attacker may be able to search workspace content, read pages and databases, enumerate users, create or modify content, archive pages, delete blocks, or delete managed connections.

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction that prints the complete API key.

  • Test only whether the environment variable is present:

    shell
    if [ -n "${MATON_API_KEY:-}" ]; then
      echo "MATON_API_KEY is configured"
    else
      echo "MATON_API_KEY is not configured"
    fi
    
  • If identification is necessary, display only a short, non-sensitive fingerprint rather than the key itself.

  • Add explicit guidance prohibiting credentials from being included in logs, screenshots, support tickets, or agent transcripts.

  • Configure CI and agent environments to redact MATON_API_KEY from command output.

  • Rotate any API key that has already been printed into persistent or shared output.

  • Apply least-privilege permissions to the OAuth connection associated with each key.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:15
Finding

Broad Notion Access Delegated Through a Third-Party Authentication Proxy

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-27
Vulnerability Type: Broad third-party access and privilege-boundary exposure
Risk Level: Medium

Vulnerable Code Snippet:

text
Base URL
https://gateway.maton.ai/notion/{native-api-path}


Replace {native-api-path} with the actual Notion API endpoint path. The gateway proxies requests to api.notion.com and automatically injects your OAuth token.

Required Headers

All Notion API requests require:

Notion-Version: 2025-09-03
Authorization: Bearer $MATON_API_KEY
Content-Type: application/json

Technical Analysis

The Skill routes all documented Notion operations through gateway.maton.ai instead of communicating directly with api.notion.com. The documentation explicitly states that the gateway injects the user's Notion OAuth token. Consequently, the proxy is placed inside the authentication and data-access trust boundary: it receives API requests and content while controlling the credentials used against Notion.

The same Skill documents broad read and mutation capabilities, including workspace search, user enumeration, page and database creation, schema modification, page archival, block deletion, and OAuth connection deletion. The documentation does not establish least-privilege scopes, separate read-only access from destructive access, or require user confirmation before destructive operations.

This behavior is disclosed rather than concealed, and the reviewed file does not prove malicious conduct by the service. Nevertheless, it creates a significant third-party trust and privilege concentration risk: compromise or misuse of the Maton API key or gateway could expose every operation allowed by the associated OAuth connection.

Attack Path

  1. A user creates or activates a Notion OAuth connection through Maton.
  2. The connection is granted access to Notion pages, databases, users, or workspace content.
  3. The user or agen ...[truncated 1092 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer direct communication with the official Notion API and direct Notion OAuth when managed proxying is not required.
  • If the proxy is required, document the third-party trust boundary, credential custody model, data retention policy, logging behavior, and incident-response process.
  • Request only the minimum Notion permissions and share only the resources needed for the task.
  • Use separate credentials or connections for read-only and write/destructive operations.
  • Require explicit user confirmation immediately before page archival, block deletion, schema modification, or connection deletion.
  • Restrict API keys by environment, account, permitted connection, operation, and expiration time where supported.
  • Rotate keys regularly and revoke them immediately after suspected disclosure.
  • Maintain auditable records of gateway operations and alert on unusual searches, bulk reads, destructive changes, or connection deletion.
  • Avoid transmitting unrelated sensitive workspace content through the proxy.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
Quick Start
Search for pages
curl -X POST https://gateway.maton.ai/notion/v1/search \
  -H "Authorization: Bearer $MATON_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Notion-Version: 2025-09-03" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents multiple state-changing and destructive operations such as updating data sources, creating databases/pages, archiving pages, appending block children, and deleting blocks, but it does not clearly warn users that these actions can permanently modify or remove workspace content. In an agent context, this increases the risk of unintended destructive actions being taken on behalf of a user, especially if the skill is invoked broadly or without confirmation gates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.