Back to skill

Security audit

Notion命令行(免费版)

Security checks across malware telemetry and agentic risk

Overview

This Notion CLI skill is generally purpose-aligned, but it can modify or delete Notion content and its activation/safety guidance is too broad for that level of authority.

Install only if you intentionally want an agent to operate your Notion workspace from the terminal. Verify the CLI package source before installing, use a least-privilege Notion integration shared only with the databases needed, and require explicit confirmation before updates, archives, deletions, alias changes, comments, or exports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger condition is overly broad and can cause the agent to invoke this skill for generic project-management or collaboration requests, even when the user did not specifically intend Notion CLI operations. In a skill with read/write/exec capabilities and destructive commands such as update, archive, delete, alias remove, and block-delete, overbroad activation increases the chance of unintended data modification or disclosure.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents multiple state-changing and destructive operations without an upfront warning that actions can modify or delete Notion pages, blocks, comments, or aliases. In the context of a terminal-integrated skill with exec/write permissions, this omission makes accidental destructive actions more likely, especially when an AI agent is choosing commands on the user's behalf.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.