notion-cli

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but the install and trust story is not fully coherent because the `ntn` npm package was not verified as an official Notion CLI. Since the skill forwards a Notion API token into that CLI and supports remote file/worker operations, the main concern is supply-chain and credential-forwarding risk rather than confirmed malware.

Confidence: 82%Severity: 80%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:18 PM
Package URL
pkg:socket/skills-sh/makenotion%2Fskills%2Fnotion-cli%2F@fd490b7dbd0e6e00854f94c9e3d6226194cadd2a