Security policy
August 13, 2026 ยท View on GitHub
Reporting a vulnerability
Report configuration or documentation vulnerabilities through a private GitHub security advisory. Do not publish unpatched security details in an issue. If a credential was exposed, revoke it before reporting and do not include the live value.
Scope
This repository contains a static integration overlay and documentation. The browser-tool implementation, DSH runtime, browser binaries, and authentication systems are maintained separately; report defects in those components to their respective maintainers.
Browser automation is network-capable and may write screenshots containing sensitive page content. Use least-privilege browser profiles, restrict network egress, protect the screenshot directory, and retain human approval for sensitive operations.