notion-research-documentation
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Outsider free text can enter the LLM via the runtime path
Notion:notion-search→Notion:notion-fetch, which retrieves and skims Notion page body text authored by other people (e.g., other users’ pages) for synthesis and citation.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (medium risk: 0.60). The skill directs the agent to add/enable a remote MCP, edit a local config.toml, and perform login commands—operations that modify local configuration and enable remote access, so it changes machine state and poses moderate risk even though it doesn't request sudo or create users.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata