notion-cli

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it relies on a third-party CLI and a pipe-to-shell installer from a custom domain, then routes a Notion API token and potentially local files/project contents through that tool. This is not clearly malicious, but the install trust and credential-forwarding model are disproportionate compared with using Notion’s official API directly.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/makenotion%2Fskills%2Fnotion-cli%2F@4360360f674f12699a66fffa1ab80174abbca93b