notion

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This package is documentation for a Notion integration that intentionally proxies Notion API calls through Maton-managed endpoints and manages OAuth connections centrally. There is no evidence in the provided content of obfuscated code, reverse shells, or explicit exfiltration routines. The primary security concern is the intentional forwarding and centralized storage of sensitive credentials and OAuth tokens at Maton domains (gateway.maton.ai, ctrl.maton.ai, connect.maton.ai), which increases attack surface and trust dependencies compared to direct Notion API usage. Users should treat Maton as a high-trust third party, avoid printing raw responses in insecure environments, and evaluate Maton's security/privacy policies before adopting this integration.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:24 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fnotion%2F@3974d6b43dbb513c5848eff7fc66731834759af0