notion

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches Notion access, and the npm install path appears proportionate, but the core integration routes credentials and workspace actions through ClawLink rather than directly to Notion. That third-party mediation creates notable data-flow and trust risk even without clear evidence of malware.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fnotion%2F@e4a73d614174fc6d634257beeb2a0ca82e005e2191d17895ecf56ce1cecf0d85
Security Audit — socket — notion