Skip to content

Security: fevra-dev/Stiletto

Security

SECURITY.md

Security Policy

⚠️ Responsible Use

This tool is designed for authorized security testing only.

Authorized Use Cases

  • ✅ Testing your own applications
  • ✅ Penetration testing with written permission
  • ✅ Bug bounty programs (within scope)
  • ✅ Educational/research environments
  • ✅ Capture The Flag (CTF) competitions

Prohibited Use Cases

  • ❌ Testing systems without authorization
  • ❌ Exploiting vulnerabilities for personal gain
  • ❌ Accessing or exfiltrating data without permission
  • ❌ Denial of service attacks
  • ❌ Any illegal activities

🔒 Reporting Security Vulnerabilities

If you discover a security vulnerability in this tool itself:

  1. Do NOT open a public GitHub issue
  2. Email details to: [security contact]
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We will respond within 48 hours and work with you to address the issue.

📋 Supported Versions

Version Supported
2.0.x ✅ Current
1.x.x ❌ No longer supported

🛡️ Security Best Practices

When using this tool:

  1. Always get written permission before testing
  2. Document your testing scope clearly
  3. Use in isolated environments when possible
  4. Protect API keys (use environment variables)
  5. Review logs for sensitive data before sharing
  6. Report findings responsibly to asset owners

📜 Legal Disclaimer

The authors of this software are not responsible for any misuse or damage caused by this program. Users are solely responsible for ensuring they have proper authorization before using this tool.

Unauthorized access to computer systems is illegal in most jurisdictions and can result in severe penalties including fines and imprisonment.

There aren’t any published security advisories