Atlas / MCP servers / awkoy / Notion

NotionCAUTION

mcp/awkoy/notion-2

Notion MCP server for Claude, Cursor, ChatGPT & Claude Desktop. Connect AI agents to Notion via Model Context Protocol — pages, databases, blocks, comments, files.

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
173
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/notion-mcp-server)

Give your AI read/write access to Notion with one token and one command. Claude Code, Claude Desktop, Cursor, VS Code, Cline, Zed, anything that speaks MCP: it can create pages, query databases, append blocks, apply templates, comment and upload files, in plain language.

Notion ships its own MCP server. Where this one differs:

  • It authenticates with a token, so it runs headless. Notion's hosted MCP is OAuth-only and someone has to click "Authorize". This one works in CI, cron jobs, background agents and self-hosted deployments.
  • It doesn't spend your context on tool schemas. The official open-source server loads 24 endpoint schemas into the model's context at connection: 17,163 tokens, re-sent with every request for the rest of the session. This one loads three tools, 1,005 tokens — 94% less, 17× smaller — and fetches an operation's schema only when a task actually touches it.
  • It doesn't spend your context on answers either. Reading the same pages through both servers, pulling a page's content costs 82% less (26,071 → 4,568 tokens on an 88-block page), a 25-row database query 81% less, a page object 68% less. Notion's raw JSON is mostly id/type wrappers, annotations, and created_by/parent/icon blocks, and none of it reaches the model. That is the half that compounds, because a tool surface is paid once and responses are paid on every call. Measured against a reproducible fixture, with the caveats stated →

Nothing is lost to get

Read from source at commit 4ba112bba8efOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add notion-mcp-server --env NOTION_TOKEN=${NOTION_TOKEN} -- npx -y [email protected]
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
notion_describeread
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/types/emoji.ts:45
| "😶🌫️"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/types/emoji.ts:46
| "😶🌫"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/types/emoji.ts:51
| "😮💨"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/types/emoji.ts:68
| "😵💫"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/types/emoji.ts:145
| "❤️🔥"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/index.ts:8
const pkg = require("../../package.json") as { version: string };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/files.test.ts:634
source: { type: "path", path: "../../etc/passwd" },
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/get-image.test.ts:163
"https://169.254.169.254/latest/meta-data/",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:267
# -> notion-mcp-server vX.Y.Z running on http://127.0.0.1:3000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:289
curl http://127.0.0.1:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:291
npx @modelcontextprotocol/inspector --transport http --server-url http://127.0.0.1:3000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:319
test: ["CMD", "node", "-e", "fetch('http://127.0.0.1:'+(process.env.PORT||3000)+'/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/get-image.test.ts:163
"https://169.254.169.254/latest/meta-data/",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@notionhq/client, remark-gfm, remark-parse, unified, zod, @types/mdast, @types/node, shx
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:24
- **MCP protocol revision 2026-07-28, over HTTP and stdio.** The server now serves the stateless generation of the protocol next to the 2024-11-05 ... 2025-11-25 one, choosing per request from what th
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:77
- **Server logs reach the MCP client.** The server only ever logged with `console.error`, and most clients hide a server's stderr — VS Code, MCP Inspector and Claude Desktop show `notifications/messag
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:176
- **Streamable HTTP transport.** The server can now run as a remote/hosted endpoint in addition to stdio. Set `MCP_TRANSPORT=http` (default stays `stdio`) to serve the MCP Streamable HTTP protocol at
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:270
It serves MCP **Streamable HTTP** on `/mcp` for both current protocol generations, picked per request from what the client sends. **MCP 2026-07-28** clients get the stateless path, where every `POST`
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 4ba112bba8effull audit observations/trust-audit/mcp-server/awkoy__notion-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-064ba112bba8efCAUTIONB83first audit
06

Questions

What is the Notion MCP server?

Notion MCP server for Claude, Cursor, ChatGPT & Claude Desktop. Connect AI agents to Notion via Model Context Protocol — pages, databases, blocks, comments, files.

What tools does Notion expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Notion safe to connect to an agent?

With care. The audit graded it B (83/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Notion need?

It reads NOTION_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Notion run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as notion-mcp-server at 3.1.2.

How current is this page?

The grade is for one exact copy of the source (4ba112bba8ef), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement