Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to store a long-lived Notion API key in a plaintext file under ~/.config/notion/api_key and immediately use it in authenticated API calls, but it provides no warning about local secret exposure or about sending workspace content to a third-party service. This is dangerous because other local users, backup systems, logs, or malware may recover the token, and users may unknowingly transmit sensitive page or database contents to Notion.
