Security fixes are currently made only on the latest main branch. No stable release line has
been declared yet.
Do not open a public issue for a vulnerability. Use GitHub's private vulnerability reporting and include:
- affected commit or version;
- component and operating-system build;
- reproduction steps or a minimal proof of concept;
- expected impact;
- suggested mitigation, if known.
Do not include real credentials, private camera images, unredacted local IP addresses or personal calibration data. You should receive an initial response when the maintainer reviews the report; response times are not currently guaranteed.
- The hand controller processes camera frames locally and does not intentionally save or upload them.
- Both control modes can generate real Win32 mouse input after the safety lock is opened.
- The eye-control UDP protocol is intentionally limited to trusted private networks and is not encrypted or authenticated in the current version.
- The application does not request administrator privileges and cannot inject input into higher integrity processes under the normal Windows security model.
- Portable binaries are currently unsigned. Verify release checksums and obtain archives only from the official repository.
Reports that demonstrate an unexpected way around these boundaries are especially useful.