Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README tells users to export a Notion Internal Integration Token but does not clearly warn that the token is a sensitive credential that grants API access to any pages and databases shared with the integration. In an agent skill context, users may paste or expose environment setup details into logs, shells, or automation environments, increasing the chance of credential leakage and unauthorized access to workspace content.
