Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to store a long-lived Notion API token in plaintext under ~/.config/notion/api_key without mentioning file permissions, OS keychains, rotation, or the sensitivity of the secret. While this is a common convenience pattern, it increases the chance of local credential disclosure through other local users, backups, shell tooling, or unrelated malware reading the file.
