notion-cli
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is plausible, but the install and trust story is not fully coherent because the `ntn` npm package was not verified as an official Notion CLI. Since the skill forwards a Notion API token into that CLI and supports remote file/worker operations, the main concern is supply-chain and credential-forwarding risk rather than confirmed malware.
Confidence: 82%Severity: 80%
Audit Metadata