If you discover a security vulnerability in zombie-killer-tray, please report it privately through GitHub Security Advisories or directly via email:
- Primary Security Contact:
security@dev-bricks.org - Umbrella Security Team:
security@open-bricks.org
Please do not report security vulnerabilities via public GitHub issues, discussions, or pull requests. Do not include private command-line arguments, hostnames, or system credentials in report descriptions.
We operate under an explicit, standardized dual-tier Security Response Service Level Agreement:
- Initial Acknowledgment: Within 48 hours of report receipt.
- Triage & Remediation Plan: Within 5 business days of confirmation.
zombie-killer-tray is built with a defense-in-depth, fail-closed architecture to prevent accidental termination of legitimate user or system processes:
- Local-First & Zero-Egress (INV-LOCAL-01): The utility performs 100% offline local operations. It initiates no outbound network connections and emits zero telemetry.
- Unprivileged Mode for Inspection (
RunAsInvoker/ INV-SEC-02): Read-only verification (--check) runs in unprivileged user mode. Elevated privileges are only requested when launching the tray to enable termination of orphaned system/service processes. - Dead-Parent Verification (INV-PARENT-03): Reaping occurs only if the parent process PID is verified dead in multiple sampling rounds and immediately prior to termination.
- Two-Sample Stability (INV-STABLE-04): Requires two consecutive snapshots with zero CPU delta and identical creation timestamps to avoid interfering with active tasks.
- Retained Kernel Handle (INV-HANDLE-05): Holds a Win32 process handle to prevent PID-reuse race conditions.
- Strict Allowlist (INV-ALLOW-06): Only exact, verified MCP servers and language server executables/modules are eligible for termination.
- No Blanket Process Tree Termination (INV-NOTREE-07): Does not execute blanket recursive process tree kills (
taskkill /T). - Pre-Termination Audit Logging (INV-AUDIT-08): Every candidate termination is logged to
zombie_events.jsonlprior to invoking the termination API. If audit logging fails, the process is not terminated. - Minimum Process Age Gate (INV-AGE-09): Processes must exceed a minimum runtime threshold (default: 30 minutes) before being considered for termination.
This software is provided free of charge as open-source software under the MIT License. In accordance with statutory German law (§ 521 BGB - Gefälligkeitsrecht / liability for gratuitous services), liability for defects in quality and title is limited to cases of fraudulent concealment of defects, gross negligence, or intentional misconduct.