notion
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose matches Notion access, and the npm install path appears proportionate, but the core integration routes credentials and workspace actions through ClawLink rather than directly to Notion. That third-party mediation creates notable data-flow and trust risk even without clear evidence of malware.
Confidence: 85%Severity: 66%
Audit Metadata