please use GitHub's security advisories or email security@trycap.dev (pgp key) to report any security issues.
if you find bots in the wild bypassing Cap Instrumentation's headless browser checks, please email me too so i can take a look.
security advisories found from ai scans are not currently allowed due to large amounts of low-quality issues.
for "CAPTCHA bypasses", a working fix is strictly required.