whytop is designed to inspect processes without changing them. Session snapshots, questions, and answers are kept in memory, and evidence sent to the configured model excludes environment variables and secrets.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository when available. If it is unavailable, contact the repository owner through GitHub with the subject whytop security report and include:
- the affected version or commit;
- operating system and runtime details;
- reproduction steps or a proof of concept; and
- the likely impact.
Please allow time for a fix before public disclosure. Do not include real secrets or private process data in a report.