notion-mcp
Warn
Audited by Snyk on Aug 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In the Notion MCP skill, the agent’s runtime workflow only reads Notion content by using explicit workspace identifiers (e.g.,
retrieve_block_children/retrieve_database) or by searching within the user’s workspace for an explicitquery, rather than passively ingesting outsider-authored free text from public feeds/queues.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata