Repository navigation
Frequently Asked Questions
No. Its current scope is authorized reconnaissance, scanner orchestration, and reporting. Contributions that add destructive or unauthorized behavior are out of scope.
No. Public accessibility is not authorization. Obtain explicit permission and follow the defined assessment scope.
The main bot uses Docker-out-of-Docker to start disposable scanner containers on the host Docker daemon. This keeps scanner dependencies out of the main image, but creates a powerful security boundary.
Not with the current Helm chart by default. The Deployment mounts
/var/run/docker.sock and expects a compatible Docker daemon.
The current GitHub Actions workflow publishes the main Lophiarch image. Nmap, Ffuf, and Nuclei worker images are currently built separately.
The MCP server keeps current scan results in process memory. PDF files are
written to generated_reports/. A successful PDF generation clears the
in-memory scan data.
An empty result can be caused by target formatting, DNS, connectivity, authorization-scoped firewalls, scanner behavior, rate limits, or genuinely empty findings. See Troubleshooting.
Yes, when it has a legitimate authorized reconnaissance or defensive-security use case. Open the Scanner or tool integration issue form first.
You may use Lophiarch under either the MIT License or Apache License 2.0:
MIT OR Apache-2.0.
No. GitHub sponsorship supports open-source maintenance. Guaranteed support, custom integrations, deployment, and consulting are separate commercial services.
Use the repository's private vulnerability reporting flow when available or follow the email instructions in the Security Policy. Do not open a public issue.