Microsoft Copilot security directory
Notion (Independent Publisher)
Published by Chandra Sekhar & Harshini Varma
High risk
Notion connector use the API to access Notion's pages, databases, and users.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 16 tools or capabilities.
- Append block children
- Create a page
- Create comment
- Delete a block
- List of all users
- Query a database
- Retrieve a block
- Retrieve a database
- Retrieve a page
- Retrieve a page property item
- Retrieve block children
- Retrieve comments
- Retrieve User
- Retrieve your token's bot user
- Search
- Update a block
The interactive security report will load automatically.