Windows Computer Use takes security seriously. Face recognition is optional and only exposed when WINDOWS_COMPUTER_USE_MCP_ENABLE_FACE=1 and the face extra are installed (see docs/SAFETY.md Β§5). Core desktop automation does not require it.
If you discover a security vulnerability, please report it responsibly:
- Email: security@example.com (replace with actual security contact)
- Response Time: We aim to respond within 48 hours
- Disclosure: We follow responsible disclosure practices
When reporting a vulnerability, please provide:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fixes (if any)
- Your contact information for follow-up
- Opt-in: Runtime flag
WINDOWS_COMPUTER_USE_MCP_ENABLE_FACEplusfaceextra β seedocs/SAFETY.md. - Encrypted storage: Face data is stored with strong encryption
- Local-only: Intended for local operator-presence workflows; data does not leave the machine by design
- Process Isolation: Automation operations are sandboxed
- Input Validation: All user inputs are validated and sanitized
- Error Handling: Secure error messages that don't leak sensitive information
- Local Only: By default, server only accepts local connections
- Authentication: Optional JWT-based authentication for API endpoints
- HTTPS Support: SSL/TLS encryption when configured
- Run in Virtual Environment: Use virtual environments to isolate the installation
- Limit Permissions: Run with minimal required Windows permissions
- Network Access: Only expose the server on localhost unless necessary
- Regular Updates: Keep Windows Computer Use and dependencies updated
- Code Review: All changes undergo security review
- Dependency Scanning: Automated vulnerability scanning of dependencies
- Input Validation: Validate all inputs and sanitize outputs
- Error Handling: Implement proper error handling without information leakage
- Dependency vulnerability scanning
- Static code analysis for security issues
- Input validation testing
- Authentication and authorization testing
- Code review for security implications
- Architecture security assessment
- Penetration testing of exposed endpoints
- Dependency Vulnerabilities: Monitored via GitHub Dependabot
- Code Quality: Static analysis with security-focused linters
- Test Coverage: Security-critical paths have comprehensive test coverage
- Critical Updates: Released within 7 days of discovery
- Regular Updates: Security patches included in regular releases
- Backporting: Critical fixes backported to supported versions
.envfiles contain sensitive configuration- Never commit secrets or credentials
- Use environment variables for sensitive data
- Stored in
data/known_faces/directory - Encrypted using industry-standard algorithms
- Local storage only, no cloud transmission
Windows Computer Use should not be used for:
- Unauthorized access to systems
- Malware or virus creation
- Privacy violations
- Automated attacks or testing without permission
- Any illegal activities
For security-related questions or concerns:
- Check existing documentation first
- Review GitHub Issues for similar concerns
- Contact maintainers through appropriate channels
Security is a collaborative effort. We appreciate the security research community for their contributions to keeping open source software secure.
This security policy applies to Windows Computer Use and its associated repositories.