Skip to content

Disclaimer & Legal

Melvin PETIT edited this page Jun 17, 2026 · 1 revision

Disclaimer & Legal

Authorized use only

Kraken is provided for educational purposes and authorized security testing only. You must have explicit, written permission from the owner of any system before you test it. Unauthorized scanning, enumeration or vulnerability testing is illegal in most jurisdictions and can carry serious civil and criminal penalties.

The author and maintainers accept no responsibility for misuse or for any damage resulting from the use of this software. By using Kraken you agree that you are solely responsible for your actions and for ensuring you have proper authorization.

Scope discipline

  • Test only the assets that are in scope for your engagement.
  • Respect rate limits and avoid denial-of-service conditions; the parallelism controls (e.g. KRAKEN_WEB_JOBS) exist partly so you can stay gentle on a target. See Configuration.
  • Keep evidence: every session records a kraken.log audit trail and timestamped reports. See Output Structure.

Reporting security issues in Kraken

Do not open public GitHub issues for vulnerabilities in the wrapper itself. Follow the disclosure process in SECURITY.md in the repository.

License

Kraken is released under the MIT License. You are free to use, modify and redistribute it; please keep the attribution to Melvin PETIT / WhiteMuush. See the LICENSE file in the repository for the full text.

Clone this wiki locally