notion-mcp (w-10-m/notion-mcp) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 23 tools. No publisher has claimed this listing.
MCP server with 23 tools for full Notion integration, enabling database, page, block, user, search, comment, template, and duplication operations through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
w-10-m
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
notion_get_databaseGet database by ID
notion_query_databaseQuery database pages
notion_create_databaseCreate a new database
notion_update_databaseUpdate database properties
notion_get_pageGet page by ID
notion_create_pageCreate a new page. Note: Creating pages directly in workspace root requires special permissions - use database or page parents instead.
notion_update_pageUpdate page properties
notion_get_page_propertyGet page property by ID
notion_get_block_childrenGet block children
notion_append_block_childrenAppend blocks to a parent block
notion_get_blockGet block by ID
notion_update_blockUpdate block content
notion_delete_blockDelete a block
notion_list_usersList all users
notion_get_userGet user by ID
notion_get_meGet current bot user
notion_searchSearch pages and databases
notion_create_commentCreate a comment on a page or block
notion_get_commentsGet comments for a page or block
notion_create_page_from_templateCreate a new page by copying blocks from a template page
notion_create_database_from_templateCreate a new database by copying schema from a template database
notion_duplicate_pageDuplicate an existing page with its content blocks
notion_duplicate_databaseDuplicate an existing database with its schema
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios: Header Injection via Prototype Pollution
Allocation of Resources Without Limits or Throttling in Axios
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CORETEXT_USERCORS_ORIGINAllowed CORS originLOG_INGESTION_API_KEYLOG_INGESTION_URLLOG_LEVELLOG_SHIPPING_BATCH_SIZELOG_SHIPPING_ENABLEDLOG_SHIPPING_INTERVALLOG_SHIPPING_MAX_RETRIESLOG_SHIPPING_REQUIRE_API_KEYNOTION_ACCESS_TOKENyour_notion_access_token_hereORGANIZATION_IDPROJECT_IDTRANSPORT_MODEhttp PORT=3000 npm startPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
23/23 tools missing one or more hints — notion_get_database (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); notion_query_database (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); notion_create_database (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +20 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Shell command execution
20 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 10 high severity in production deps — axios@1.13.6 (high), axios@1.13.6 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Domain consistency
npm scope @west10tech doesn't match GitHub owner w-10-m
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/w-10-m/notion-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check