Please report security issues privately to the maintainers before public disclosure.
Automation capabilities that navigate, click, type, download, upload, or access browser state are security-sensitive. Reports about policy bypasses, credential leakage, unsafe defaults, and stale-action execution are in scope.