Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The script reads a local Notion API key from disk and performs an authenticated external request, which creates credential-access and network-exfiltration behavior inside a helper script. While this appears functionally related to fetching Notion tasks for a morning briefing, it is still risky because the script provides no consent prompt, validation, or minimization controls around use of the credential and transmission of workspace data.
