Back to skill

Security audit

Notion MCP

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Notion integration that can read and modify Notion content through Maton, with explicit approval guidance for connections and writes.

Install only if you are comfortable connecting Maton to the intended Notion workspace. Prefer OAuth, choose the narrowest Notion scopes available, pin the intended connection/profile when multiple accounts exist, and review every create, update, move, database schema change, comment, trash, or delete-related payload before approving it. Avoid MATON_API_KEY unless the CLI cannot be used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The documentation states that for pages outside a database, only the `title` property is allowed, yet the schema accepts arbitrary property names and values. This mismatch can enable malformed or unintended write operations, weaken downstream validation assumptions, and make it easier for an agent or prompt-influenced caller to submit unsupported metadata that could produce confusing behavior or unauthorized-looking data manipulation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.