Skip to content

Security: luSkyl/winctl

Security

SECURITY.md

Security Policy

Supported Versions

This repository currently supports the latest 0.1.x release line.

Important Safety Notes

WinCtl can observe and control a real Windows desktop. Treat it as a powerful automation tool, not a sandbox.

  • Do not run it unattended on an administrator session.
  • Do not use it for payments, account changes, password entry, 2FA, or destructive actions without explicit human confirmation.
  • Prefer --expect-title or --expect-process when targeting a specific application.
  • Use a dedicated low-privilege user account and a dedicated browser profile for autonomous workflows.

Reporting a Vulnerability

If you find a security issue, open a private security advisory or contact the maintainers privately instead of filing a public issue.

There aren't any published security advisories