I'm suspicious of their methodology:
> Open DevTools (F12), go to the Network tab, and interact with their AI feature. If you see: api.openai.com, api.anthropic.com, api.cohere.ai You’re looking at a wrapper. They might have middleware, but the AI isn’t theirs.
But... everyone knows that you shouldn't make requests directly to those hosts from your web frontend because doing so exposes your API key in a way that can be stolen by attackers.
If you have "middleware" that's likely to solve that particular problem - but then how can you investigate by intercepting traffic?
Something doesn't smell right about this investigation.
It does later say:
> I found 12 companies that left API keys in their frontend code.
So that's 12 companies, but what about the rest?