notion-cli-mcp
Installation
SKILL.md
notion-cli-mcp
Agent-first Notion access via the notion-cli binary (Rust, MIT). A single tool that serves both a shell CLI and an MCP stdio server with an explicit three-tier privilege model.
Three-tier privilege model
notion-cli mcp exposes three mutually exclusive tiers, selected by flag:
| Flag | Tier | Tool count | Intended audience |
|---|---|---|---|
| (none) | Read-only (default) | 7 | General agents — page reads, queries, search, identity check |
--allow-write |
Runtime writes | 13 | Agents that mutate existing content (pages, blocks, data-source contents) |
--allow-admin |
Admin lifecycle | 18 | Operator-facing — schema mutation, relation wiring, page relocation, db update |
--allow-admin is tool-exposure policy, not a security sandbox. An agent running in an environment with an admin-scoped Notion integration token plus arbitrary code execution can hit the REST API directly regardless of MCP gating. What the flag actually provides:
- Prompt-injection attenuation — admin tools are absent from the agent's planning surface when the server is run in a lower tier, so a hijacked agent cannot choose an admin action.
- Accidental-action prevention — default Hermes/Claude profiles expose no admin tools, so an operator can't fat-finger a schema drop through an agent intended to be read/write only.