notion-workspace

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the snippet is not overtly malicious, but the stated Notion workspace purpose is only partially aligned with the documented runtime, which authenticates solely to the AI Skills backend and does not show a direct Notion API flow. Same-brand backend use lowers supply-chain concern, yet the indirect data path, overrideable base URL, and missing runner code make the skill a medium security risk.

Confidence: 80%Severity: 57%
Audit Metadata
Analyzed At
Mar 23, 2026, 04:06 PM
Package URL
pkg:socket/skills-sh/allinherog-star%2Fai-skills%2Fnotion-workspace%2F@287644604faded7f8239659d42ac6385948aae65