skills/skills.volces.com/notion-cli-mcp

notion-cli-mcp

Installation
SKILL.md

notion-cli-mcp

Agent-first Notion access via the notion-cli binary (Rust, MIT). A single tool that serves both a shell CLI and an MCP stdio server with an explicit three-tier privilege model.

Three-tier privilege model

notion-cli mcp exposes three mutually exclusive tiers, selected by flag:

Flag Tier Tool count Intended audience
(none) Read-only (default) 7 General agents — page reads, queries, search, identity check
--allow-write Runtime writes 13 Agents that mutate existing content (pages, blocks, data-source contents)
--allow-admin Admin lifecycle 18 Operator-facing — schema mutation, relation wiring, page relocation, db update

--allow-admin is tool-exposure policy, not a security sandbox. An agent running in an environment with an admin-scoped Notion integration token plus arbitrary code execution can hit the REST API directly regardless of MCP gating. What the flag actually provides:

  • Prompt-injection attenuation — admin tools are absent from the agent's planning surface when the server is run in a lower tier, so a hijacked agent cannot choose an admin action.
  • Accidental-action prevention — default Hermes/Claude profiles expose no admin tools, so an operator can't fat-finger a schema drop through an agent intended to be read/write only.
Installs
2
First Seen
May 4, 2026
notion-cli-mcp from skills.volces.com