Skip to content

Security: ElwinLiu/handless

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

If you discover a security vulnerability in Handless, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use GitHub Security Advisories to report the vulnerability privately.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

What to expect

  • Acknowledgment within 48 hours
  • A fix or mitigation plan within 7 days for critical issues
  • Credit in the release notes (unless you prefer anonymity)

Scope

Since Handless runs entirely offline and processes audio locally, the primary security concerns are:

  • Local privilege escalation
  • Unauthorized access to microphone or clipboard data
  • Malicious model files
  • Dependencies with known vulnerabilities

There aren’t any published security advisories