notion

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Notion API skill appears well-aligned with its stated purpose: it manipulates Notion resources via authenticated HTTP requests using a locally stored API key. The footprint is proportionate, with credential handling confined to local storage and legitimate API calls to a well-known service. No suspicious or high-risk data exfiltration patterns are evident; no unverifiable binaries or third-party installs are involved. Overall, the skill is BENIGN with low to moderate security risk, primarily due to credential handling in local files and potential logging exposure if not carefully managed.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 11:06 AM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fnotion%2F@a204066a1b42215ed42c62ccdbdec497aaceb524