career-ops-plugin-notion
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow
node plugins.mjs run notion search "<query>", the agent reads free-text records from a user’s Notion “Applications” database viaclient.findRecords()→queryDB()→summarize()(company/role/status/url are ingested from Notion pages), and Notion page content can be outsider-authored by anyone with access to that database.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata