Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README explicitly instructs users to capture authentication tokens using an HTTPS proxy, which encourages interception of highly sensitive session credentials without any warning about account takeover, token leakage, or handling of decrypted traffic. In the context of a reverse-engineered unofficial API, this is more dangerous because users may normalize unsafe credential collection practices and store reusable tokens that grant ongoing access to family/calendar data.
