npm/@notionhq/notion-mcp-server
graded version 2.4.1 · litmus-v6 · 2026-06-24
Adoption 70/100 · 483K npm/mo · as of 2026-06-26
- C-01 Tool-output injection
- pass
- C-02 Permission / egress overreach
- pass
- C-03 Sensitive-data handling
- pass
- C-04 Adversarial-input handling
- pass
tool-defs fingerprint · 0x126582…9a83d
Why A: All four categories passed. No injection, no data leak, no egress overreach, and adversarial inputs were handled cleanly (A means no overreach, not no network).
Adoption signals
The 70 / 100 adoption score blends the raw signals below — downloads, stars, dependents and release velocity — normalized across every tracked server. It measures reach, not safety; the litmus grade is the safety verdict. See the methodology.
- npm downloads (30d)
- 482,630
- GitHub stars
- 4,461
- Forks
- 586
- Contributors
- 22
- Dependents (deps.dev)
- 0
- Smithery installs
- 2,572
- Last published
- 2026-06-22
Reproduce this grade
The harness is open and deterministic. Re-run it against the same server and compare the grade and fingerprint — a false grade is falsifiable, not merely disputable.
npx -p @polygraphso/litmus polygraphso-litmus npm/@notionhq/notion-mcp-serverEmbed this badge
Drop it in a README, docs site, or package page. It always shows the current published grade and links back here.
[](https://polygraph.so/mcp/npm/@notionhq/notion-mcp-server)<a href="https://polygraph.so/mcp/npm/@notionhq/notion-mcp-server"><img src="https://polygraph.so/api/badge?server=npm/@notionhq/notion-mcp-server" alt="polygraph grade"></a>[](https://polygraph.so/mcp/npm/@notionhq/notion-mcp-server)