notion

Fail

Audited by Snyk on Aug 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill instructs the agent to read or accept a Notion API key (from env or user paste) and then include that secret verbatim in Authorization headers and curl command args, which forces the LLM to emit secret values in its outputs.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 16, 2026, 05:53 PM
Issues
2
Security Audit — snyk — notion