Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The documentation explicitly tells users to write the Notion API key to a plaintext file under ~/.config/notion/api_key, which can expose the credential to other local users, backups, shell tooling, or accidental disclosure. Because this is a long-lived API secret for a cloud service, insecure storage increases the chance of account or workspace compromise if the file is read or exfiltrated.
