Notchlet reads the credentials the agent CLIs keep on your Mac to query their usage endpoints, and reads their chat logs to find leaked keys. Anything that could leak those credentials or findings, send them anywhere unexpected, or widen what the app reads is a security issue.
Please do not open a public issue for vulnerabilities. Use GitHub private vulnerability reporting instead. You should get a response within a week.