top | item 45303966

Lethal Trifecta – Using Notion AI's Web Search Tool to Leak Private Notion Pages

2 points| coderinsan | 5 months ago |codeintegrity.ai

2 comments

order

coderinsan|5 months ago

Hey HN — yesterday Notion released AI agent support on their platform with support for MCP servers and custom AI agents. It didn’t take us long to find an example of a lethal trifecta attack in which, through indirect prompt injection, we were able to get Notion AI to leak data via its web search tool.