notion-cli
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it relies on a third-party CLI and a pipe-to-shell installer from a custom domain, then routes a Notion API token and potentially local files/project contents through that tool. This is not clearly malicious, but the install trust and credential-forwarding model are disproportionate compared with using Notion’s official API directly.
Confidence: 84%Severity: 74%
Audit Metadata