Is "notion-readonly-mcp-server" on MCP Registry Safe to Install?

taewoong1378 · mcp · v1.0.9

Optimized read-only MCP server for Notion API with asynchronous processing

Risk Assessment

Analyzed
100
out of 100
CRITICAL

467 security findings detected across all analyzers

MCP server analyzed for tool poisoning, prompt injection, and data exfiltration

Severity Breakdown

12
Critical
75
High
350
Medium
0
Low
0
Info

Finding Categories

61
Malware Signatures
13
Secrets
3
Network
344
IoC Indicators

YARA Rules Matched

14 rules(61 hits)
postinstall environment access postinstall system command postinstall file download postinstall network communication postinstall file manipulation postinstall obfuscation credential env files NoUseEval NoDisableSanitizeHtml UsingCommandLineArguments postinstall registry modification OriginsNotVerified NoUseWeakRandom postinstall crypto operations

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

About This Extension

Optimized read-only MCP server for Notion API with asynchronous processing

Detailed Findings

123 total

YARA Rule Matches

14 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
23
IP Addresses
8
Domains
315
Strings
344

All Indicators · 344

Domain
detected Domain: g.open

XIOC detected Domain: g.open

extracted_from_files

Hash
detected MD5 Hash: 8a6b35e6e67f802fa7e1d27686f017f2

XIOC detected MD5 Hash: 8a6b35e6e67f802fa7e1d27686f017f2

extracted_from_files

Hash
detected MD5 Hash: 41117fd769a54694bc07c1e3a682c857

XIOC detected MD5 Hash: 41117fd769a54694bc07c1e3a682c857

extracted_from_files

Hash
detected MD5 Hash: 0e5235bf86aa4efb93aa772cce7eab71

XIOC detected MD5 Hash: 0e5235bf86aa4efb93aa772cce7eab71

extracted_from_files

URL
detected URL: https://www.notion.so/bc1211cae3f14939ae34260b16f627c

XIOC detected URL: https://www.notion.so/bc1211cae3f14939ae34260b16f627c

extracted_from_files

URL
detected URL: https://developers.notion.com/reference/page#all-property-values)

XIOC detected URL: https://developers.notion.com/reference/page#all-property-values)

extracted_from_files

URL
detected URL: http://notion.so/41117fd769a54694bc07c1e3a682c857

XIOC detected URL: http://notion.so/41117fd769a54694bc07c1e3a682c857

extracted_from_files

URL
detected URL: http://api.notion.com/v1/pages/0e5235bf86aa4efb93aa772cce7eab71/properties/NVv

XIOC detected URL: http://api.notion.com/v1/pages/0e5235bf86aa4efb93aa772cce7eab71/properties/NVv

extracted_from_files

URL
detected URL: http://api.notion.com/v1/pages/0e5235bf86aa4efb93aa772cce7eab71/properties/y%7D~p?start_cursor=1QaTunT5&page_size=25

XIOC detected URL: http://api.notion.com/v1/pages/0e5235bf86aa4efb93aa772cce7eab71/properties/y%7D~p?start_cursor=1QaTunT5&page_size=25

extracted_from_files

URL
detected URL: http://test-api.com',

XIOC detected URL: http://test-api.com',

extracted_from_files

Domain
detected Domain: u.data.next

XIOC detected Domain: u.data.next

extracted_from_files

URL
detected URL: https://github.com/snaggle-ai/openapi-mcp-server.

XIOC detected URL: https://github.com/snaggle-ai/openapi-mcp-server.

extracted_from_files

URL
detected URL: http://test.com',

XIOC detected URL: http://test.com',

extracted_from_files

Domain
detected Domain: a.data.next

XIOC detected Domain: a.data.next

extracted_from_files

URL
detected URL: http://ns.adobe.com/exif/1.0/

XIOC detected URL: http://ns.adobe.com/exif/1.0/

extracted_from_files

Domain
detected Domain: vnd.ruckus.download

XIOC detected Domain: vnd.ruckus.download

extracted_from_files

URL
detected URL: http://ns.adobe.com/tiff/1.0/

XIOC detected URL: http://ns.adobe.com/tiff/1.0/

extracted_from_files

URL
detected URL: https://github.com/Taewoong1378/notion-readonly-mcp-server/issues

XIOC detected URL: https://github.com/Taewoong1378/notion-readonly-mcp-server/issues

extracted_from_files

Domain
detected Domain: vnd.sealed.net

XIOC detected Domain: vnd.sealed.net

extracted_from_files

URL
detected URL: https://github.com/Taewoong1378/notion-readonly-mcp-server#readme

XIOC detected URL: https://github.com/Taewoong1378/notion-readonly-mcp-server#readme

extracted_from_files

IP
detected Domain: fo.prototype.pipe.call

XIOC detected Domain: fo.prototype.pipe.call

extracted_from_files

Domain
detected Domain: vd.call

XIOC detected Domain: vd.call

extracted_from_files

Domain
detected Domain: www.notion.so

XIOC detected Domain: www.notion.so

extracted_from_files

Domain
detected Domain: glama.ai

XIOC detected Domain: glama.ai

extracted_from_files

IP
detected IP: ::d

XIOC detected IP: ::d

extracted_from_files

IP
detected IP: 5::

XIOC detected IP: 5::

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: vnd.antix.game

XIOC detected Domain: vnd.antix.game

extracted_from_files

Domain
detected Domain: vnd.amazon.mobi

XIOC detected Domain: vnd.amazon.mobi

extracted_from_files

Domain
detected Domain: vnd.ahead.space

XIOC detected Domain: vnd.ahead.space

extracted_from_files

Domain
detected Domain: vnd.adobe.flash.movie

XIOC detected Domain: vnd.adobe.flash.movie

extracted_from_files

Domain
detected Domain: vnd.3m.post

XIOC detected Domain: vnd.3m.post

extracted_from_files

Domain
detected Domain: vnd.3gpp.mc

XIOC detected Domain: vnd.3gpp.mc

extracted_from_files

Domain
detected Domain: emergencycalldata.ecall.msd

XIOC detected Domain: emergencycalldata.ecall.msd

extracted_from_files

Domain
detected Domain: vnd.ctct.ws

XIOC detected Domain: vnd.ctct.ws

extracted_from_files

Domain
detected Domain: vnd.collection.next

XIOC detected Domain: vnd.collection.next

extracted_from_files

Domain
detected Domain: vnd.citationstyles.style

XIOC detected Domain: vnd.citationstyles.style

extracted_from_files

Domain
detected Domain: vnd.canon

XIOC detected Domain: vnd.canon

extracted_from_files

Domain
detected Domain: vnd.cab

XIOC detected Domain: vnd.cab

extracted_from_files

Domain
detected Domain: vnd.bint.med

XIOC detected Domain: vnd.bint.med

extracted_from_files

Domain
detected Domain: vnd.apache.arrow.stream

XIOC detected Domain: vnd.apache.arrow.stream

extracted_from_files

Domain
detected Domain: vnd.eprints.data

XIOC detected Domain: vnd.eprints.data

extracted_from_files

Domain
detected Domain: vnd.drive

XIOC detected Domain: vnd.drive

extracted_from_files

Domain
detected Domain: vnd.dolby.mobile

XIOC detected Domain: vnd.dolby.mobile

extracted_from_files

Domain
detected Domain: vnd.desmume.movie

XIOC detected Domain: vnd.desmume.movie

extracted_from_files

IP
detected Domain: vnd.dece.zip

XIOC detected Domain: vnd.dece.zip

extracted_from_files

Domain
detected Domain: vnd.dece.data

XIOC detected Domain: vnd.dece.data

extracted_from_files

URL
detected Domain: vnd.curl.car

XIOC detected Domain: vnd.curl.car

extracted_from_files

Domain
detected Domain: vnd.ibm.secure

XIOC detected Domain: vnd.ibm.secure

extracted_from_files

Domain
detected Domain: vnd.gov.sk

XIOC detected Domain: vnd.gov.sk

extracted_from_files

Domain
detected Domain: vnd.gmx

XIOC detected Domain: vnd.gmx

extracted_from_files

Domain
detected Domain: vnd.fujixerox.art

XIOC detected Domain: vnd.fujixerox.art

extracted_from_files

Domain
detected Domain: vnd.f-secure.mobile

XIOC detected Domain: vnd.f-secure.mobile

extracted_from_files

Domain
detected Domain: vnd.eudora.data

XIOC detected Domain: vnd.eudora.data

extracted_from_files

Domain
detected Domain: vnd.eu.kasparian.car

XIOC detected Domain: vnd.eu.kasparian.car

extracted_from_files

Domain
detected Domain: vnd.nokia.n-gage.ac

XIOC detected Domain: vnd.nokia.n-gage.ac

extracted_from_files

Domain
detected Domain: vnd.muvee.style

XIOC detected Domain: vnd.muvee.style

extracted_from_files

Domain
detected Domain: vnd.ms

XIOC detected Domain: vnd.ms

extracted_from_files

Domain
detected Domain: vnd.llamagraphics.life-balance.exchange

XIOC detected Domain: vnd.llamagraphics.life-balance.exchange

extracted_from_files

Domain
detected Domain: vnd.is

XIOC detected Domain: vnd.is

extracted_from_files

Domain
detected Domain: vnd.ims.lti.v2.toolproxy.id

XIOC detected Domain: vnd.ims.lti.v2.toolproxy.id

extracted_from_files

Domain
detected Domain: vnd.ieee

XIOC detected Domain: vnd.ieee

extracted_from_files

Domain
detected Domain: vnd.openblox.game

XIOC detected Domain: vnd.openblox.game

extracted_from_files

Domain
detected Domain: vnd.oma.poc.final

XIOC detected Domain: vnd.oma.poc.final

extracted_from_files

Domain
detected Domain: vnd.oma.group

XIOC detected Domain: vnd.oma.group

extracted_from_files

Domain
detected Domain: vnd.oma.cab

XIOC detected Domain: vnd.oma.cab

extracted_from_files

Domain
detected Domain: vnd.oasis.opendocument.graphics

XIOC detected Domain: vnd.oasis.opendocument.graphics

extracted_from_files

Domain
detected Domain: vnd.nokia.radio

XIOC detected Domain: vnd.nokia.radio

extracted_from_files

Domain
detected Domain: vnd.nokia.n-gage.data

XIOC detected Domain: vnd.nokia.n-gage.data

extracted_from_files

Domain
detected Domain: vnd.rs

XIOC detected Domain: vnd.rs

extracted_from_files

Domain
detected Domain: vnd.route66.link

XIOC detected Domain: vnd.route66.link

extracted_from_files

Domain
detected Domain: vnd.rainstor.data

XIOC detected Domain: vnd.rainstor.data

extracted_from_files

Domain
detected Domain: vnd.previewsystems.box

XIOC detected Domain: vnd.previewsystems.box

extracted_from_files

Domain
detected Domain: vnd.poc.group

XIOC detected Domain: vnd.poc.group

extracted_from_files

Domain
detected Domain: vnd.openxmlformats-package.digital

XIOC detected Domain: vnd.openxmlformats-package.digital

extracted_from_files

Domain
detected Domain: vnd.openstreetmap.data

XIOC detected Domain: vnd.openstreetmap.data

extracted_from_files

Domain
detected Domain: vnd.cmles.radio

XIOC detected Domain: vnd.cmles.radio

extracted_from_files

Domain
detected Domain: vnd.youtube.yt

XIOC detected Domain: vnd.youtube.yt

extracted_from_files

Domain
detected Domain: vnd.uplanet.channel

XIOC detected Domain: vnd.uplanet.channel

extracted_from_files

Domain
detected Domain: vnd.syncml.dm

XIOC detected Domain: vnd.syncml.dm

extracted_from_files

Domain
detected Domain: vnd.nokia.mobile

XIOC detected Domain: vnd.nokia.mobile

extracted_from_files

Domain
detected Domain: vnd.hns.audio

XIOC detected Domain: vnd.hns.audio

extracted_from_files

Domain
detected Domain: vnd.dolby.pl

XIOC detected Domain: vnd.dolby.pl

extracted_from_files

Domain
detected Domain: vnd.net

XIOC detected Domain: vnd.net

extracted_from_files

IP
detected Domain: vnd.rip

XIOC detected Domain: vnd.rip

extracted_from_files

Domain
detected Domain: a.next

XIOC detected Domain: a.next

extracted_from_files

Domain
detected Domain: vnd.sun.xml.writer.global

XIOC detected Domain: vnd.sun.xml.writer.global

extracted_from_files

Domain
detected Domain: r.map

XIOC detected Domain: r.map

extracted_from_files

Domain
detected Domain: vnd.digital

XIOC detected Domain: vnd.digital

extracted_from_files

Domain
detected Domain: vnd.dece.audio

XIOC detected Domain: vnd.dece.audio

extracted_from_files

Domain
detected Domain: vnd.wap.si

XIOC detected Domain: vnd.wap.si

extracted_from_files

Domain
detected Domain: vnd.sun.j2me.app

XIOC detected Domain: vnd.sun.j2me.app

extracted_from_files

Domain
detected Domain: vnd.in3d.spot

XIOC detected Domain: vnd.in3d.spot

extracted_from_files

Domain
detected Domain: vnd.in

XIOC detected Domain: vnd.in

extracted_from_files

Domain
detected Domain: vnd.fly

XIOC detected Domain: vnd.fly

extracted_from_files

Domain
detected Domain: vnd.abc

XIOC detected Domain: vnd.abc

extracted_from_files

Domain
detected Domain: vnd.gs

XIOC detected Domain: vnd.gs

extracted_from_files

Domain
detected Domain: vnd.motorola.video

XIOC detected Domain: vnd.motorola.video

extracted_from_files

Domain
detected Domain: vnd.hns.video

XIOC detected Domain: vnd.hns.video

extracted_from_files

Domain
detected Domain: vnd.dece.video

XIOC detected Domain: vnd.dece.video

extracted_from_files

Domain
detected Domain: vnd.dece.sd

XIOC detected Domain: vnd.dece.sd

extracted_from_files

Domain
detected Domain: vnd.dece.mp

XIOC detected Domain: vnd.dece.mp

extracted_from_files

Domain
detected Domain: vnd.dece.mobile

XIOC detected Domain: vnd.dece.mobile

extracted_from_files

Domain
detected Domain: vnd.wap.sl

XIOC detected Domain: vnd.wap.sl

extracted_from_files

Domain
detected Domain: n.jobs

XIOC detected Domain: n.jobs

extracted_from_files

Domain
detected Domain: this.jobs

XIOC detected Domain: this.jobs

extracted_from_files

Domain
detected Domain: e.jobs

XIOC detected Domain: e.jobs

extracted_from_files

Domain
detected Domain: vnd.vivo

XIOC detected Domain: vnd.vivo

extracted_from_files

Domain
detected Domain: vnd.uvvu.mp

XIOC detected Domain: vnd.uvvu.mp

extracted_from_files

Domain
detected Domain: vnd.sealedmedia.softseal.mov

XIOC detected Domain: vnd.sealedmedia.softseal.mov

extracted_from_files

Domain
detected Domain: vnd.nokia.mp

XIOC detected Domain: vnd.nokia.mp

extracted_from_files

Domain
detected Domain: jn.call

XIOC detected Domain: jn.call

extracted_from_files

Domain
detected Domain: mh.call

XIOC detected Domain: mh.call

extracted_from_files

Domain
detected Domain: nh.call

XIOC detected Domain: nh.call

extracted_from_files

Domain
detected Domain: function.prototype.call

XIOC detected Domain: function.prototype.call

extracted_from_files

Domain
detected Domain: object.prototype.propertyisenumerable.call

XIOC detected Domain: object.prototype.propertyisenumerable.call

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: i.jobs

XIOC detected Domain: i.jobs

extracted_from_files

Domain
detected Domain: tx.call

XIOC detected Domain: tx.call

extracted_from_files

Domain
detected Domain: t.host

XIOC detected Domain: t.host

extracted_from_files

Domain
detected Domain: t.call

XIOC detected Domain: t.call

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

Domain
detected Domain: wa.call

XIOC detected Domain: wa.call

extracted_from_files

Domain
detected Domain: r.name

XIOC detected Domain: r.name

extracted_from_files

Domain
detected Domain: document.documentelement.style

XIOC detected Domain: document.documentelement.style

extracted_from_files

Domain
detected Domain: we.storage

XIOC detected Domain: we.storage

extracted_from_files

Domain
detected Domain: we.save

XIOC detected Domain: we.save

extracted_from_files

IP
detected Domain: n.skips.map

XIOC detected Domain: n.skips.map

extracted_from_files

Domain
detected Domain: n.save

XIOC detected Domain: n.save

extracted_from_files

Domain
detected Domain: n.formatargs.call

XIOC detected Domain: n.formatargs.call

extracted_from_files

Domain
detected Domain: re.call

XIOC detected Domain: re.call

extracted_from_files

Domain
detected Domain: e.search

XIOC detected Domain: e.search

extracted_from_files

Domain
detected Domain: e.host

XIOC detected Domain: e.host

extracted_from_files

Domain
detected Domain: px.call

XIOC detected Domain: px.call

extracted_from_files

Domain
detected Domain: ar.call

XIOC detected Domain: ar.call

extracted_from_files

Domain
detected Domain: te.save

XIOC detected Domain: te.save

extracted_from_files

Domain
detected Domain: iterm.app

XIOC detected Domain: iterm.app

extracted_from_files

Domain
detected Domain: ee.ci

XIOC detected Domain: ee.ci

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

Domain
detected Domain: i.next

XIOC detected Domain: i.next

extracted_from_files

Domain
detected Domain: qx.call

XIOC detected Domain: qx.call

extracted_from_files

Domain
detected Domain: n.search

XIOC detected Domain: n.search

extracted_from_files

Domain
detected Domain: l.host

XIOC detected Domain: l.host

extracted_from_files

Domain
detected Domain: o.host

XIOC detected Domain: o.host

extracted_from_files

Domain
detected Domain: l.data

XIOC detected Domain: l.data

extracted_from_files

Domain
detected Domain: i.name

XIOC detected Domain: i.name

extracted_from_files

Domain
detected Domain: pairs.map

XIOC detected Domain: pairs.map

extracted_from_files

Domain
detected Domain: a.call

XIOC detected Domain: a.call

extracted_from_files

Domain
detected Domain: s.name

XIOC detected Domain: s.name

extracted_from_files

Domain
detected Domain: o.call

XIOC detected Domain: o.call

extracted_from_files

Domain
detected Domain: this.name

XIOC detected Domain: this.name

extracted_from_files

Domain
detected Domain: error.call

XIOC detected Domain: error.call

extracted_from_files

Domain
detected Domain: e.stream

XIOC detected Domain: e.stream

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: i.data

XIOC detected Domain: i.data

extracted_from_files

Domain
detected Domain: n.call

XIOC detected Domain: n.call

extracted_from_files

Domain
detected Domain: i.call

XIOC detected Domain: i.call

extracted_from_files

Domain
detected Domain: e.map

XIOC detected Domain: e.map

extracted_from_files

Domain
detected Domain: o.name

XIOC detected Domain: o.name

extracted_from_files

Domain
detected Domain: a.search

XIOC detected Domain: a.search

extracted_from_files

Domain
detected Domain: ie.map

XIOC detected Domain: ie.map

extracted_from_files

Domain
detected Domain: i.host

XIOC detected Domain: i.host

extracted_from_files

Domain
detected Domain: e.headers.host

XIOC detected Domain: e.headers.host

extracted_from_files

Domain
detected Domain: v.protocols.map

XIOC detected Domain: v.protocols.map

extracted_from_files

Domain
detected Domain: r.total

XIOC detected Domain: r.total

extracted_from_files

Domain
detected Domain: n.name

XIOC detected Domain: n.name

extracted_from_files

Domain
detected Domain: t.read

XIOC detected Domain: t.read

extracted_from_files

Domain
detected Domain: this.tools

XIOC detected Domain: this.tools

extracted_from_files

Domain
detected Domain: a.data

XIOC detected Domain: a.data

extracted_from_files

Domain
detected Domain: tg.read

XIOC detected Domain: tg.read

extracted_from_files

Domain
detected Domain: e.data

XIOC detected Domain: e.data

extracted_from_files

Domain
detected Domain: n.host

XIOC detected Domain: n.host

extracted_from_files

Domain
detected Domain: ce.data

XIOC detected Domain: ce.data

extracted_from_files

Domain
detected Domain: gp.call

XIOC detected Domain: gp.call

extracted_from_files

Domain
detected Domain: v.call

XIOC detected Domain: v.call

extracted_from_files

Domain
detected Domain: i.response.data

XIOC detected Domain: i.response.data

extracted_from_files

Domain
detected Domain: fr.call

XIOC detected Domain: fr.call

extracted_from_files

Domain
detected Domain: o.id

XIOC detected Domain: o.id

extracted_from_files

Domain
detected Domain: uy.call

XIOC detected Domain: uy.call

extracted_from_files

URL
detected URL: https://github.com/evanw/esbuild/pull/2067

XIOC detected URL: https://github.com/evanw/esbuild/pull/2067

extracted_from_files

URL
detected URL: https://api.notion.com

XIOC detected URL: https://api.notion.com

extracted_from_files

Domain
detected Domain: dy.call

XIOC detected Domain: dy.call

extracted_from_files

Domain
detected Domain: yaml.org

XIOC detected Domain: yaml.org

extracted_from_files

Domain
detected Domain: e.mark.name

XIOC detected Domain: e.mark.name

extracted_from_files

Domain
detected Domain: e.post

XIOC detected Domain: e.post

extracted_from_files

Domain
detected Domain: p.next

XIOC detected Domain: p.next

extracted_from_files

Domain
detected Domain: t.map

XIOC detected Domain: t.map

extracted_from_files

Domain
detected Domain: e.replacer.call

XIOC detected Domain: e.replacer.call

extracted_from_files

Domain
detected Domain: mu.call

XIOC detected Domain: mu.call

extracted_from_files

Domain
detected Domain: array.prototype.slice.call

XIOC detected Domain: array.prototype.slice.call

extracted_from_files

Domain
detected Domain: ot.call

XIOC detected Domain: ot.call

extracted_from_files

Domain
detected Domain: e.onwarning.call

XIOC detected Domain: e.onwarning.call

extracted_from_files

Domain
detected Domain: yy.call

XIOC detected Domain: yy.call

extracted_from_files

Domain
detected Domain: xy.call

XIOC detected Domain: xy.call

extracted_from_files

Domain
detected Domain: w.next

XIOC detected Domain: w.next

extracted_from_files

Domain
detected Domain: u.next

XIOC detected Domain: u.next

extracted_from_files

Domain
detected Domain: s.call

XIOC detected Domain: s.call

extracted_from_files

Domain
detected Domain: l.next

XIOC detected Domain: l.next

extracted_from_files

Domain
detected Domain: r.call

XIOC detected Domain: r.call

extracted_from_files

Domain
detected Domain: n.replacer.call

XIOC detected Domain: n.replacer.call

extracted_from_files

Domain
detected Domain: bu.call

XIOC detected Domain: bu.call

extracted_from_files

Domain
detected Domain: me.name

XIOC detected Domain: me.name

extracted_from_files

Domain
detected Domain: ut.next

XIOC detected Domain: ut.next

extracted_from_files

Domain
detected Domain: ge.in

XIOC detected Domain: ge.in

extracted_from_files

Domain
detected Domain: yn.name

XIOC detected Domain: yn.name

extracted_from_files

Domain
detected Domain: cs.call

XIOC detected Domain: cs.call

extracted_from_files

Domain
detected Domain: kn.next

XIOC detected Domain: kn.next

extracted_from_files

Domain
detected Domain: c.call

XIOC detected Domain: c.call

extracted_from_files

Domain
detected Domain: ge.next

XIOC detected Domain: ge.next

extracted_from_files

Domain
detected Domain: l.call

XIOC detected Domain: l.call

extracted_from_files

Domain
detected Domain: z.next

XIOC detected Domain: z.next

extracted_from_files

Domain
detected Domain: q.in

XIOC detected Domain: q.in

extracted_from_files

Domain
detected Domain: q.name

XIOC detected Domain: q.name

extracted_from_files

Domain
detected Domain: p.call

XIOC detected Domain: p.call

extracted_from_files

Domain
detected Domain: me.in

XIOC detected Domain: me.in

extracted_from_files

Domain
detected Domain: k.map

XIOC detected Domain: k.map

extracted_from_files

Domain
detected Domain: a.map

XIOC detected Domain: a.map

extracted_from_files

Domain
detected Domain: i.definition.security

XIOC detected Domain: i.definition.security

extracted_from_files

Domain
detected Domain: v.security

XIOC detected Domain: v.security

extracted_from_files

Domain
detected Domain: h.call

XIOC detected Domain: h.call

extracted_from_files

Domain
detected Domain: gn.next

XIOC detected Domain: gn.next

extracted_from_files

Domain
detected Domain: m.call

XIOC detected Domain: m.call

extracted_from_files

Domain
detected Domain: e.items.map

XIOC detected Domain: e.items.map

extracted_from_files

Domain
detected Domain: n.data

XIOC detected Domain: n.data

extracted_from_files

Domain
detected Domain: t.data

XIOC detected Domain: t.data

extracted_from_files

Domain
detected Domain: o.data

XIOC detected Domain: o.data

extracted_from_files

Domain
detected Domain: this.data

XIOC detected Domain: this.data

extracted_from_files

Domain
detected Domain: s.unionerrors.map

XIOC detected Domain: s.unionerrors.map

extracted_from_files

Domain
detected Domain: k.date

XIOC detected Domain: k.date

extracted_from_files

Domain
detected Domain: def.in

XIOC detected Domain: def.in

extracted_from_files

Domain
detected Domain: u.data

XIOC detected Domain: u.data

extracted_from_files

Domain
detected Domain: c.data

XIOC detected Domain: c.data

extracted_from_files

Domain
detected Domain: def.rest

XIOC detected Domain: def.rest

extracted_from_files

Domain
detected Domain: p.data

XIOC detected Domain: p.data

extracted_from_files

Domain
detected Domain: s.map

XIOC detected Domain: s.map

extracted_from_files

Domain
detected Domain: i.map

XIOC detected Domain: i.map

extracted_from_files

Domain
detected Domain: c.in

XIOC detected Domain: c.in

extracted_from_files

Domain
detected Domain: c.name

XIOC detected Domain: c.name

extracted_from_files

Domain
detected Domain: r.properties

XIOC detected Domain: r.properties

extracted_from_files

Domain
detected Domain: capabilities.tools

XIOC detected Domain: capabilities.tools

extracted_from_files

Domain
detected Domain: t.error.data

XIOC detected Domain: t.error.data

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

Domain
detected Domain: stdin.off

XIOC detected Domain: stdin.off

extracted_from_files

Domain
detected Domain: t.allof.map

XIOC detected Domain: t.allof.map

extracted_from_files

Domain
detected Domain: t.anyof.map

XIOC detected Domain: t.anyof.map

extracted_from_files

Domain
detected Domain: t.oneof.map

XIOC detected Domain: t.oneof.map

extracted_from_files

Domain
detected Domain: a.properties

XIOC detected Domain: a.properties

extracted_from_files

Domain
detected Domain: t.properties

XIOC detected Domain: t.properties

extracted_from_files

Domain
detected Domain: c.response.data

XIOC detected Domain: c.response.data

extracted_from_files

Domain
detected Domain: m.data

XIOC detected Domain: m.data

extracted_from_files

Domain
detected Domain: t.page

XIOC detected Domain: t.page

extracted_from_files

Domain
detected Domain: i.id

XIOC detected Domain: i.id

extracted_from_files

Domain
detected Domain: formschema.properties

XIOC detected Domain: formschema.properties

extracted_from_files

Domain
detected Domain: inputschema.properties

XIOC detected Domain: inputschema.properties

extracted_from_files

URL
detected URL: https://website.domain/images/image.png

XIOC detected URL: https://website.domain/images/image.png

extracted_from_files

Domain
detected Domain: c.properties

XIOC detected Domain: c.properties

extracted_from_files

Domain
detected Domain: s.properties

XIOC detected Domain: s.properties

extracted_from_files

Domain
detected Domain: s.id

XIOC detected Domain: s.id

extracted_from_files

Domain
detected Domain: r.id

XIOC detected Domain: r.id

extracted_from_files

Domain
detected Domain: a.id

XIOC detected Domain: a.id

extracted_from_files

Domain
detected Domain: h.page

XIOC detected Domain: h.page

extracted_from_files

Domain
detected Domain: x.id

XIOC detected Domain: x.id

extracted_from_files

Domain
detected Domain: u.map

XIOC detected Domain: u.map

extracted_from_files

Domain
detected Domain: x.data

XIOC detected Domain: x.data

extracted_from_files

Domain
detected Domain: 6g.es

XIOC detected Domain: 6g.es

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: m.next

XIOC detected Domain: m.next

extracted_from_files

URL
detected URL: http://test.com'

XIOC detected URL: http://test.com'

extracted_from_files

URL
detected URL: https://api.example.com'

XIOC detected URL: https://api.example.com'

extracted_from_files

IP
detected IP: ::1

XIOC detected IP: ::1

extracted_from_files

Domain
detected Domain: 2.sm

XIOC detected Domain: 2.sm

extracted_from_files

Domain
detected Domain: d2.pg

XIOC detected Domain: d2.pg

extracted_from_files

Domain
detected Domain: ͳi.sv

XIOC detected Domain: ͳi.sv

extracted_from_files

Domain
detected Domain: 5.pt

XIOC detected Domain: 5.pt

extracted_from_files

Domain
detected Domain: b.uz

XIOC detected Domain: b.uz

extracted_from_files

Domain
detected Domain: i.ad

XIOC detected Domain: i.ad

extracted_from_files

Domain
detected Domain: 0.sd

XIOC detected Domain: 0.sd

extracted_from_files

Domain
detected Domain: esbuild.build

XIOC detected Domain: esbuild.build

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: app.post

XIOC detected Domain: app.post

extracted_from_files

Domain
detected Domain: p.id

XIOC detected Domain: p.id

extracted_from_files

Domain
detected Domain: req.params.id

XIOC detected Domain: req.params.id

extracted_from_files

Domain
detected Domain: ܓ.ac

XIOC detected Domain: ܓ.ac

extracted_from_files

Domain
detected Domain: k.ne

XIOC detected Domain: k.ne

extracted_from_files

Domain
detected Domain: response.data

XIOC detected Domain: response.data

extracted_from_files

Domain
detected Domain: express.express

XIOC detected Domain: express.express

extracted_from_files

Domain
detected Domain: uploadpath.post

XIOC detected Domain: uploadpath.post

extracted_from_files

Domain
detected Domain: test.com

XIOC detected Domain: test.com

extracted_from_files

Domain
detected Domain: api.notion.com

XIOC detected Domain: api.notion.com

extracted_from_files

Domain
detected Domain: notion.so

XIOC detected Domain: notion.so

extracted_from_files

Domain
detected Domain: developers.notion.com

XIOC detected Domain: developers.notion.com

extracted_from_files

Domain
detected Domain: param.name

XIOC detected Domain: param.name

extracted_from_files

Domain
detected Domain: error.data

XIOC detected Domain: error.data

extracted_from_files

Domain
detected Domain: test-api.com

XIOC detected Domain: test-api.com

extracted_from_files

Domain
detected Domain: mockresponse.data

XIOC detected Domain: mockresponse.data

extracted_from_files

Domain
detected Domain: api.example.com

XIOC detected Domain: api.example.com

extracted_from_files

Domain
detected Domain: createresponse.data.id

XIOC detected Domain: createresponse.data.id

extracted_from_files

Domain
detected Domain: response.data.id

XIOC detected Domain: response.data.id

extracted_from_files

Domain
detected Domain: data.id

XIOC detected Domain: data.id

extracted_from_files

Domain
detected Domain: backgroundresulttool.name

XIOC detected Domain: backgroundresulttool.name

extracted_from_files

Domain
detected Domain: onepagertool.name

XIOC detected Domain: onepagertool.name

extracted_from_files

Domain
detected Domain: method.name

XIOC detected Domain: method.name

extracted_from_files

Domain
detected Domain: result.tools

XIOC detected Domain: result.tools

extracted_from_files

Domain
detected Domain: error.response.data

XIOC detected Domain: error.response.data

extracted_from_files

Domain
detected Domain: param.in

XIOC detected Domain: param.in

extracted_from_files

Domain
detected Domain: cacheddata.id

XIOC detected Domain: cacheddata.id

extracted_from_files

Domain
detected Domain: enrichedblock.page

XIOC detected Domain: enrichedblock.page

extracted_from_files

Domain
detected Domain: block.id

XIOC detected Domain: block.id

extracted_from_files

Domain
detected Domain: batch.map

XIOC detected Domain: batch.map

extracted_from_files

Domain
detected Domain: pagedata.properties

XIOC detected Domain: pagedata.properties

extracted_from_files

Domain
detected Domain: params.page

XIOC detected Domain: params.page

extracted_from_files

Domain
detected Domain: comment.id

XIOC detected Domain: comment.id

extracted_from_files

Domain
detected Domain: method.inputschema.properties

XIOC detected Domain: method.inputschema.properties

extracted_from_files

Domain
detected Domain: response.next

XIOC detected Domain: response.next

extracted_from_files

Domain
detected Domain: response.data.next

XIOC detected Domain: response.data.next

extracted_from_files

Domain
detected Domain: initialresponse.data.next

XIOC detected Domain: initialresponse.data.next

extracted_from_files

Domain
detected Domain: initialresponse.data

XIOC detected Domain: initialresponse.data

extracted_from_files

Domain
detected Domain: pagedata.id

XIOC detected Domain: pagedata.id

extracted_from_files

Domain
detected Domain: cacheddata.properties

XIOC detected Domain: cacheddata.properties

extracted_from_files

Domain
detected Domain: schema.properties

XIOC detected Domain: schema.properties

extracted_from_files

Domain
detected Domain: expected.tools

XIOC detected Domain: expected.tools

extracted_from_files

Domain
detected Domain: tools.api.methods.map

XIOC detected Domain: tools.api.methods.map

extracted_from_files

Domain
detected Domain: p.name

XIOC detected Domain: p.name

extracted_from_files

Domain
detected Domain: m.name

XIOC detected Domain: m.name

extracted_from_files

Domain
detected Domain: expected.name

XIOC detected Domain: expected.name

extracted_from_files

Domain
detected Domain: actual.name

XIOC detected Domain: actual.name

extracted_from_files

Domain
detected Domain: bodyschema.properties

XIOC detected Domain: bodyschema.properties

extracted_from_files

Domain
detected Domain: paramobj.name

XIOC detected Domain: paramobj.name

extracted_from_files

Domain
detected Domain: mcpmethod.name

XIOC detected Domain: mcpmethod.name

extracted_from_files

Domain
detected Domain: schema.allof.map

XIOC detected Domain: schema.allof.map

extracted_from_files

Domain
detected Domain: schema.anyof.map

XIOC detected Domain: schema.anyof.map

extracted_from_files

Domain
detected Domain: schema.oneof.map

XIOC detected Domain: schema.oneof.map

extracted_from_files

Domain
detected Domain: result.properties

XIOC detected Domain: result.properties

extracted_from_files

URL
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

extracted_from_files

URL
detected URL: http://localhost

XIOC detected URL: http://localhost

extracted_from_files

URL
detected URL: https://www.notion.so/profile/integrations

XIOC detected URL: https://www.notion.so/profile/integrations

extracted_from_files

URL
detected URL: https://glama.ai/mcp/servers/@Taewoong1378/notion-readonly-mcp-server/badge

XIOC detected URL: https://glama.ai/mcp/servers/@Taewoong1378/notion-readonly-mcp-server/badge

extracted_from_files

URL
detected URL: https://glama.ai/mcp/servers/@Taewoong1378/notion-readonly-mcp-server

XIOC detected URL: https://glama.ai/mcp/servers/@Taewoong1378/notion-readonly-mcp-server

extracted_from_files

Domain
detected Domain: n.id

XIOC detected Domain: n.id

extracted_from_files

Domain
detected Domain: r.data

XIOC detected Domain: r.data

extracted_from_files

Hash
detected MD5 Hash: 1a6b35e6e67f802fa7e1d27686f017f2

XIOC detected MD5 Hash: 1a6b35e6e67f802fa7e1d27686f017f2

extracted_from_files

Domain
detected Domain: f.merge.call

XIOC detected Domain: f.merge.call

extracted_from_files

Security Analysis Summary

Security Analysis Overview

notion-readonly-mcp-server is a mcp extension published by taewoong1378. Version 1.0.9 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 467 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 12 finding(s)
  • High: 75 finding(s)
  • Medium: 350 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

notion-readonly-mcp-server is published by taewoong1378 on the mcp marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions