Brotto

Security Policy

Brotto runs an agent against your own logged-in browser, so the interesting part of its threat model is you, and the whole design is the set of gates standing between an agent holding your sessions and your documents. What Brotto does not protect you from is written down here as well, because a policy that only lists strengths is not a threat model.

Reporting a vulnerability

Email the maintainer, or open a private security advisory on the repository (“Security” → “Report a vulnerability”). Please do not open a public issue for an unfixed vulnerability.

Include: what you did, what you expected, what happened, the affected version, and your Chrome version if the issue involves the extension. A proof of concept helps a great deal.

You can expect an acknowledgement within 72 hours and a substantive reply within seven days. If a fix is warranted we will agree a disclosure date with you, and credit you in the release notes unless you would rather we did not.

Threat model

Brotto is unusual in a way that changes what “safe” means, so it is worth being explicit.

Brotto is not a sandbox. The agent operates with the full authority of the session you run it in. A malicious page, a prompt injection in page content, or a bug in Brotto can all cause actions to be taken as you. Treat a Brotto run the way you would treat handing your logged-in browser to a contractor.

What Brotto does provide:

What Brotto does not provide, and you should not assume:

Out of scope