Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The bridge transparently forwards arbitrary MCP JSON received on stdin to a remote third-party service, which means prompts, tool arguments, secrets, file contents, or other sensitive data supplied by the client may leave the local environment. Although this is the stated purpose of the bridge, the lack of an explicit consent, allowlist, redaction, or disclosure mechanism in the runtime flow creates a real data-exposure risk, especially when used by agents that assume stdio tools are purely local.
