Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly states that requests are routed through keychains.dev, which means request bodies, headers, URLs, and API responses may transit a third-party service. While the proxy is the product’s intended function, the skill does not provide an explicit warning that sensitive business data sent to upstream APIs will also be exposed to the proxy operator and governed by that third party’s privacy and retention practices.
