Skip to content

Security: albertolicea00/SlowQ

Security

SECURITY.md

πŸ”’ Security Policy

Supported Versions

Version Supported
current βœ… Yes
older ❌ No

Reporting a Vulnerability

SlowQ is a tiny utility that runs with Accessibility privileges β€” that makes security extra important.

If you find a vulnerability:

  1. Do not open a public GitHub issue
  2. Email the maintainer or reach out privately
  3. Include a clear description and reproduction steps

What we care about

  • Escalation of privileges via the event tap
  • Keystroke leakage or logging
  • Bypassing the confirmation gate
  • Injection via synthetic events

What's in scope

The Sources/ directory. The Info.plist and build configuration are assumed to be as-shipped.

You should expect an acknowledgment within 72 hours, and a fix timeline depending on severity.

Preferences

SlowQ stores its settings in UserDefaults (standard com.slowq.SlowQ domain). No data leaves your machine.


Thank you for helping keep SlowQ safe. 🐌

There aren't any published security advisories