notion

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
databases/SKILL.md

SUSPICIOUS: the visible skill is mostly aligned with its stated Notion database purpose, but it relies on an external third-party connector and a transitive prerequisite skill that are not clearly first-party Notion tooling. The main concern is opaque credential and endpoint handling in notion-connect rather than overt malicious behavior in this skill text.

Confidence: 86%Severity: 58%
AnomalyLOW
pages/SKILL.md

SUSPICIOUS. The visible functionality is proportionate to a Notion page editor, but the skill offloads authentication and setup to a separate community-published `notion-connect` skill that does not appear to be official Notion infrastructure. The core concern is transitive trust and unclear credential/data routing, not confirmed malware in this file.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:55 AM
Package URL
pkg:socket/skills-sh/CreminiAI%2Fcremini-skills%2Fnotion%2F@61620f8e739995460557fe4cd40fdea59acffdf4