notion-cli

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s Notion-focused capabilities are mostly aligned with its stated purpose, but the trust model is weak: it installs a third-party CLI from a Homebrew tap and forwards a live Notion API token from Doppler directly into that binary. With no provided evidence that the binary is officially published, open-source, and verifiably controlled by the same publisher, this meets the high-risk credential-forwarding pattern for AI skills.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fnotion-cli%2F@208a9e1be3f88874ff9c398a2bfb5643521d9aba