Microsoft Copilot security directory

Notion (Independent Publisher)

Published by Chandra Sekhar & Harshini Varma

High risk

Notion connector use the API to access Notion's pages, databases, and users.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 16 tools or capabilities.

  • Append block children
  • Create a page
  • Create comment
  • Delete a block
  • List of all users
  • Query a database
  • Retrieve a block
  • Retrieve a database
  • Retrieve a page
  • Retrieve a page property item
  • Retrieve block children
  • Retrieve comments
  • Retrieve User
  • Retrieve your token's bot user
  • Search
  • Update a block

The interactive security report will load automatically.