Back to skill

Security audit

Notion

Security checks for vulnerabilities and agentic risk

Overview

This Notion skill is a coherent ClawLink integration that clearly discloses OAuth-based access to read and modify the user's Notion workspace.

Install only if you are comfortable connecting your Notion account through ClawLink and giving the assistant access to the pages and databases available to that connection. Review write previews carefully before approving changes or deletions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.