**Notion MCP Server** is a MCP server implementation that enables AI assistants to interact with Notion's API.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
awkoy
Source: modelscope · also listed on PulseMCP, github_topic, npm, mcp.so
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
HTTPS_PROXY/ HTTP_PROXY — — Route Notion API traffic through an HTTP(S) proxy (standard env vars, lowercase also accepted)HTTP_PROXYHTTPS_PROXY / — — Route Notion API traffic through an HTTP(S) proxy (standard env vars, lowercase also accepted)NOTION_DAILY_LOG_PAGE_IDOnly used by the daily-log MCP promptNOTION_PAGE_IDDefault parent for create_page / create_database when no parent is passed (page → Share → Copy link; ID = last 32 chars)NOTION_TOKENe =ntn_paste_your_token_here \NOTION_UPLOAD_ROOThttp_proxyhttps_proxyAll four hints declared on every tool
2/2 tools missing one or more hints — notion_execute (missing: idempotentHint); notion_describe (missing: idempotentHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
Only 0/2 tool handlers declare input schemas (0%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Shell command execution
2 child_process/subprocess calls in production code — runs shell commands (benchmarks/list-tools.mjs:6, benchmarks/describe-all.mjs:3)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Secrets never reach shell commands
1 secret value passed to shell commands — possible command injection
Never pass secrets through shell commands. Use library APIs that accept credentials as arguments.
Dependency freshness
3/8 production deps abandoned (no release in 2+ years): node-fetch@2023-11-30 (2.7y), remark-parse@2023-11-20 (2.7y), unified@2024-06-19 (2.2y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/awkoy-notion-mcp-server-19zpdp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check