notion

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities fit its stated Notion purpose, and the CLI comes from an official npm package tied to the same publisher, so this is not overt malware. But all authentication and API activity are routed through Membrane rather than directly to Notion, creating a third-party credential/data trust boundary, and the unpinned global CLI install adds moderate supply-chain risk.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnotion%2F@924993c7b0aeb776bc2defe5c8d777807e7aab07