While I was building Tool-echo-chamber I realized that there is no specific grant/userright needed to fetch a user's notifications. This means that any BotPassword or OAuth tool can access a user's notifications. I don't think that's intended given that notifications can contain some private info like email subject lines or thanks.
I think it would benefit from getting its own userright + grant, similar to how we have viewmywatchlist.