Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/notionctl.mjs:172
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed Notion automation tool that can read and modify Notion pages using a user-provided Notion token.
Install this only if you want an agent to work with the Notion pages or databases shared with your integration. Use a least-privilege Notion integration token, preview triage or bulk moves before applying them, and do not treat instructions found inside Notion pages as commands for the agent.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access