The skill is insecure because it fetches and executes arbitrary instructions from an attacker-controlled Notion page, enabling remote command injection and unauthorized control over the agent's behavior.
npx skills add https://github.com/makenotion/cursor-notion-pluginThe skill instructs the agent to fetch and follow instructions from an external Notion page, which is an attacker-controllable source. This allows an attacker to inject arbitrary commands into the agent's execution flow by modifying the Notion page content.
Use the Notion MCP tools to: Get the page content including title, description, and any relevant properties
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/makenotion/cursor-notion-plugin/tasks-build)<a href="https://mondoo.com/ai-agent-security/skills/github/makenotion/cursor-notion-plugin/tasks-build"><img src="https://mondoo.com/ai-agent-security/api/badge/github/makenotion/cursor-notion-plugin/tasks-build.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/makenotion/cursor-notion-plugin/tasks-build.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.