Atlas / MCP servers / danhilse / Notion

NotionCAUTION

mcp/danhilse/notion-5

A simple MCP integration that allows Claude to read and manage a personal Notion todo list

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
4 3r · 1w · 0d
Transport
stdio
License
MIT
Stars
208
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A simple Model Context Protocol (MCP) server that integrates with Notion's API to manage my personal todo list through Claude. This is a basic implementation tailored specifically for my minimalist todo list setup in Notion.

Important Note

This is a personal project designed for a very specific use case: my simple Notion todo list that has just three properties:

  • Task (title)
  • When (select with only two options: "today" or "later")
  • Checkbox (marks if completed)

Example Notion Database

While you can use this as a starting point for your own Notion integration, you'll likely need to modify the code to match your specific database structure and requirements.

Features

  • Add new todo items
  • View all todos
  • View today's tasks
  • Check off a task as complete

Prerequisites

  • Python 3.10 or higher
  • A Notion account
  • A Notion integration (API key)
  • A Notion database that matches the exact structure described above (or willingness to modify the code for your structure)

Setup

  1. Clone the repository:
git clone https://github.com/yourusername/notion-mcp.git
cd notion-mcp
  1. Set up Python environment:
python -m venv .venv
source .venv/bin/activate  # On Windows use: .venv\Scripts\activate
uv pip install -e .
  1. Create a Notion integration:
  2. Go to https://www.notion.so/my-integrations
  3. Create new integration
  4. Copy the API key
  1. Share your database with the integration:
  2. Open your todo database in Notion
  3. Click "..." menu → "Add connections"
  4. Select your integration
  1. Create a .env file:
NOTION_API_KEY=your-api-key-here
NOTION_DATABASE_ID=your-database-id-here
  1. Configure Claude Desktop:
{
"mcpServers": {
"notion-todo": {
"command": "/path/to/your/.venv/bin/python",
Read from source at commit 497a4a64123aOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add notion_mcp --env NOTION_API_KEY=${NOTION_API_KEY} -- uvx notion_mcp
claude-desktop
{
  "mcpServers": {
    "notion_mcp": {
      "command": "uvx",
      "args": [
        "notion_mcp"
      ],
      "env": {
        "NOTION_API_KEY": "${NOTION_API_KEY}"
      }
    }
  }
}
03

Exposed tools (4)

3 read · 1 write · 0 destructive.

ToolRiskDescription
add_todowriteAdd a new todo item
complete_todoreadMark a todo item as complete
show_all_todosreadShow all todo items from Notion
show_today_todosreadShow today
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (8)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/__init__.cpython-311.pyc
__init__.cpython-311.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/__main__.cpython-311.pyc
__main__.cpython-311.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/server.cpython-311.pyc
server.cpython-311.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo.gif
assets/demo.gif
Why it matters. 2857229 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 497a4a64123afull audit observations/trust-audit/mcp-server/danhilse__notion-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06497a4a64123aCAUTIONB86first audit
06

Questions

What is the Notion MCP server?

A simple MCP integration that allows Claude to read and manage a personal Notion todo list

What tools does Notion expose?

4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Notion safe to connect to an agent?

With care. The audit graded it B (86/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Notion need?

It reads NOTION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Notion run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as notion_mcp.

How current is this page?

The grade is for one exact copy of the source (497a4a64123a), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement