notion-cli
Fail
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: In SKILL.md, the installation instructions recommend "curl -fsSL https://ntn.dev | bash". This pattern downloads and executes code from a remote source directly in the shell, which is a significant security risk as the script's contents are not verified before execution.
- [METADATA_POISONING]: The skill's LICENSE.md claims copyright by "Notion Labs, Inc." for the year 2026, while the skill is provided by the author "celeroncoder". This discrepancy, combined with the future-dated copyright, suggests deceptive metadata or potential impersonation of an official tool.
- [COMMAND_EXECUTION]: The skill provides instructions for running a variety of ntn commands that perform network operations, file uploads, and system interactions, such as "ntn files create" and "ntn workers deploy".
- [INDIRECT_PROMPT_INJECTION]: The skill includes tools to fetch content from external sources, such as Notion pages and comments via "ntn pages get ". This content is untrusted and could contain hidden instructions designed to manipulate the agent's behavior.
- Ingestion points: Page content retrieval and API responses from Notion endpoints.
- Boundary markers: The instructions lack delimiters or specific directives to ignore instructions embedded within the fetched data.
- Capability inventory: The skill can execute shell commands, perform file operations, and deploy worker capabilities.
- Sanitization: There is no evidence of input validation, escaping, or sanitization for data retrieved through the CLI.
Recommendations
- HIGH: Downloads and executes remote code from: https://ntn.dev - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata