Thanks for flagging this, appreciate it. Looked into it: 5/70 engines, and the ones naming something specific point to generic ML classifiers (Microsoft's own is Trojan:Win32/Wacatac.ml, a heuristic model well known for false-positiving on PyInstaller-packed Python apps, not a signature match). Checked the build: the published exe's hash matches what I built locally, and every bundled dependency matches the untouched packages from PyPI byte for byte, no tampering anywhere in the chain.
The proxy does things that look "suspicious" to heuristics on paper (runs a local browser in the background to solve Cloudflare, closes it afterward, listens on a local port) but that's exactly the functionality the tool is built around, nothing more. Filing a false positive report with Microsoft now. If Defender still blocks it on your end in the meantime, you'll need to allow it manually or wait for the report to clear.
