notion2CLI

Security Policy

notion2CLI is local-first, but it handles private Notion content and forwards that content to local AI runtimes. Treat it as a tool that can move sensitive material between local processes.

Supported Versions

Version Supported
0.1.x Security fixes are accepted while the MVP is active.

Reporting a Vulnerability

Please do not publish exploit details, private Notion content, bearer tokens, logs, or reproduction data in a public issue.

Preferred reporting path:

  1. Use GitHub Security Advisories for this repository if available.
  2. If private advisories are not available, open a minimal public issue asking for a secure contact path. Do not include sensitive details in that issue.

Include the affected version or commit, runtime path (codex, claude, or standalone), operating system, and a concise impact summary.

Local Bridge Threat Model

The bridge listens on 127.0.0.1 and defaults to port 43821. It is intended for same-machine use only.

Authentication and pairing:

Browser access:

Notion access:

CLI permissions:

Artifacts:

Handling Sensitive Data

Avoid running full-page jobs on pages that contain credentials, private customer data, or regulated information unless you understand how your selected runtime handles that data.

Before sharing logs or bug reports, remove: