Skip to content

Security: pradipNP/agent-racchha

Security

SECURITY.md

Security Policy

Racchha can launch applications, type text, click UI elements, and drive a browser. Treat computer-control code as safety-sensitive.

Secrets

  • Do not commit API keys, .env files, tokens, or credentials.
  • Use backend/.env.example (and the root .env.example) as placeholders only.
  • Copy examples to a local backend/.env. That file must stay untracked.
  • If a key may have been exposed, rotate it with the provider before discussing the incident in public.

Reporting a vulnerability

Please do not open a public GitHub issue for:

  • leaked secrets
  • ways to bypass the action validator
  • arbitrary code execution through Racchha
  • remotely exploitable backend issues

Email or otherwise contact the maintainers privately. Include:

  • a description of the issue
  • reproduction steps
  • affected version / commit
  • whether you believe a secret was exposed (do not paste the secret)

We will acknowledge the report and work on a fix before any public disclosure.

Computer-control safety

Contributors must not:

  • bypass backend/app/core/computer_control/action_validator.py
  • add arbitrary shell, PowerShell, CMD, or unrestricted Python execution “to make a feature easier”
  • add unrestricted coordinate clicking
  • widen application allowlists without review
  • disable observation / verification for convenience

Goal actions must remain typed ComputerAction values that pass validation.

Responsible disclosure

Give maintainers reasonable time to patch before publishing exploit details. Racchha is experimental; a cautious disclosure helps users who run it on their own Windows machines.

There aren't any published security advisories