Skip to content

Security: ca-who-codes/hack.proof

Security

SECURITY.md

Security & responsible use

Scope of use

The skills in this repo drive real security tools — scanners, fuzzers, and active exploitation frameworks. Use them only against:

  • Code, applications, infrastructure, or contracts you own, or
  • Targets you have explicit written authorization to test.

Running active scans, fuzzing, or exploitation against systems you don't own or aren't authorized to test may be illegal regardless of intent. The skills are written to prefer passive, low-impact techniques first and to flag which steps generate real traffic or can mutate a target — respect those flags.

Reporting a vulnerability in this repo

This repo is documentation and shell scripts — there's no service to compromise — but if you spot a genuinely dangerous mistake (a command that does something destructive it doesn't warn about, a script bug that could damage a target, a supply-chain risk in the bootstrap process), open an issue or PR describing it. Please don't file "this tool could be used maliciously" reports — that's inherent to security tooling and is governed by the scope rules above.

Handling findings safely

When you run these skills and they surface real secrets, credentials, or exploitable issues:

  • Don't paste full secret values into issues, PRs, chat logs, or reports — truncate them.
  • The findings/ directory is gitignored for a reason. Don't commit raw scan output; it routinely contains sensitive data about the target.
  • Treat every discovered credential as compromised and rotate it, even if the finding was in a private repo.

There aren't any published security advisories