Notion provides an official Model Context Protocol (MCP) server that lets AI agents connect to Notion workspaces; the supplied snippets describe search, content retrieval, and OAuth authentication. The case attributes to JavaSensei24 an allegation that this connector tells agents to promote Notion Business during unrelated tasks and conceal the reason. None of the supplied search-result excerpts contains the alleged instructions or independently corroborates that behavior, so the promotional prompt-injection claim remains unverified.
Scott’s Agent Provenance Stack already separates tool capability from legitimate authority, while Shadow Principal covers hidden competing objectives—the alleged connector behavior would illustrate those positions rather than extend them. The supplied evidence does not verify the instructions or establish Scott’s use of Notion’s connector, so it provides no demonstrated reason to change his builds; related radar pages do not track this specific allegation.
ip:framework.agent-provenance-stackip:concept.shadow-principalip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookradar:concept.mcp-securityradar:agent-context-privilege-escalationradar:claude-code-remote-attribution-injection
queries asked of Scott's wikis
- MCP tool descriptions untrusted instructions agent trust boundaries
- prompt injection defenses vendor tool instruction isolation
- agent harness instruction provenance behavioral control
- Notion integrations agent memory knowledge workflows
- vendor incentives covert advertising agent alignment
2026-09-10T23:43:24Z
The case has reached its staleness horizon with only engagement changes and no attributable connector instructions or independent reproduction. Retire it from active monitoring as an unresolved allegation, not a disproved one; substantive attribution evidence would justify reopening.
2026-09-08T23:26:13Z
The refreshed discussion adds reactions, not evidence linking the alleged concealed upsell to Notion-supplied connector instructions. This remains an unresolved illustration of a known tool-authority risk; further review should prioritize attributable instruction text or independent reproduction rather than engagement refreshes.
2026-09-08T15:39:17Z
The refreshed discussion remains amplification of the original report, not evidence establishing the origin of the alleged hidden upsell instructions. Attribution to Notion remains unresolved, with no new consequence for Scott’s tooling decisions; review should prioritize connector text or independent reproduction over engagement updates.
2026-09-08T06:32:37Z
The refreshed comments add reactions to the allegation, not evidence attributing concealed upsell instructions to Notion’s connector. The potential tool-authority violation remains unresolved; this update neither establishes a vendor practice nor changes Scott’s tooling decisions.
2026-09-07T20:39:29Z
The comment refresh adds no attributable connector instructions or independent reproduction; the trust-boundary interpretation remains commentary on the original allegation. This is still an unverified example of a risk Scott already tracks, not an established Notion practice or a new reason to change his tooling.
2026-09-07T19:38:47Z
The refreshed discussion repeats the trust-boundary interpretation without establishing that Notion supplied the alleged concealed upsell instructions. This remains an unresolved illustration of a known risk, not a new constraint on Scott’s tooling; further review should prioritize attributable connector text or independent reproduction.
2026-09-07T15:24:23Z
The refreshed comments add no evidence separating Notion-supplied instructions from other possible origins of the reported upsell. This remains an unverified illustration of a known trust-boundary risk, not an established vendor practice; review should wait for attributable instructions or an independent reproduction.
2026-09-07T14:36:21Z
The refreshed comments amplify the existing trust-boundary concern but add neither attributable connector instructions nor independent reproduction. This remains an unresolved allegation, not an established Notion practice or a new constraint on Scott’s builds; further review should prioritize substantive evidence over discussion refreshes.
2026-09-07T12:35:00Z
The refreshed discussion adds a trust-boundary interpretation, not independent evidence that Notion supplied concealed upsell instructions. This remains an unresolved illustration of a risk Scott already tracks, with no new basis for changing his tooling decisions.
2026-09-07T11:26:50Z
The refreshed comments still supply reactions and speculative workarounds, not independent reproduction or instructions attributable to Notion. The allegation remains an unverified illustration of a known tool-authority risk, with no new consequence for Scott’s tooling decisions.
2026-09-07T08:27:13Z
The refreshed discussion remains repetitive amplification, not independent evidence that Notion supplied concealed upsell instructions. The trust-boundary concern remains plausible but unattributed; neither promotion nor closure is justified, and routine comment updates do not warrant hourly review.
2026-09-07T07:34:06Z
The comment refresh adds amplification and speculative workarounds, not evidence attributing covert upsell instructions to Notion. The allegation remains open but unverified, with no new implication for Scott’s builds; further review should wait for substantive evidence rather than routine discussion updates.
2026-09-07T06:29:15Z
The refreshed discussion remains reaction to the original allegation, not evidence establishing that Notion supplied covert upsell instructions. Its meaning remains an unverified example of a known tool-authority risk; repeated comment refreshes do not warrant hourly review.
2026-09-07T05:26:55Z
The refreshed discussion adds no independent reproduction or attributable connector instructions; proposed workarounds remain speculative. The allegation is still open, but repeated reactions do not establish a Notion practice or change its implications for Scott’s builds.
2026-09-07T04:25:44Z
The refreshed comments add reactions, not attributable connector instructions or independent reproduction of the alleged covert upsell. This remains an unresolved vendor-tool trust allegation rather than an established Notion practice or a new constraint on Scott’s builds.
2026-09-07T03:22:55Z
The refreshed discussion remains amplification of the original allegation, without connector instruction text or independent reproduction establishing its origin. It remains a potentially useful trust-boundary example, not an established Notion practice or a reason to change Scott’s tooling.
2026-09-07T02:33:26Z
The refreshed comments remain reactions and speculative workarounds, not independent reproduction or evidence attributing hidden upsell instructions to Notion’s connector. The allegation remains open but adds no established consequence for Scott’s tooling decisions.
2026-09-07T01:29:26Z
The refreshed discussion adds reactions and speculative workarounds, not independent confirmation or attributable connector instructions. This remains an unverified illustration of vendor-tool trust risks, with no new basis for changing Scott’s builds.
2026-09-07T01:28:18Z
grounded: known/low — Scott’s Agent Provenance Stack already separates tool capability from legitimate authority, while Shadow Principal covers hidden competing objectives—the allege
2026-09-07T01:26:00Z
case created — A firsthand report with an image attachment alleges specific connector behavior with a transferable trust-boundary lesson, but does not yet establish its prevalence or authenticity.