Please do not open a public issue for security problems. Instead report privately so the issue can be fixed before disclosure.
Preferred: open a private report via GitHub Security Advisories.
If that is not possible, send details to the repository owner through a private channel.
- Registry import handlers (
Registry/,Installers/) - Launchers that spawn elevated processes (
SAITULS_LAUNCHER.cmd,Scripts/AI_AGENT_LAUNCHER.PS1,Installers/INSTALL_*.PS1) - Anything reading or writing user credentials (LIMISAW, Codex launchers)
- Product, version and where it runs (Windows 10/11 x64)
- Steps to reproduce
- Impact
- Suggested fix, if known
The owner will acknowledge reports within a few days and aims to fix confirmed issues promptly.