Skip to content

Security: rksharma-owg/shodan-recon-agent

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please do not open a public GitHub issue. Instead, report it privately:

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce
  • Any relevant logs or proof-of-concept code

We aim to acknowledge reports within 3 business days.

Supported Versions

Version Supported
0.1.x ✅

Handling of Credentials

This project never logs, persists, or transmits your Shodan API key outside of the official Shodan API endpoints. Keys are masked in all CLI output and stored locally only if you explicitly run shodan-recon configure.

Responsible Use

This tool is a thin client around the Shodan API. It does not perform any scanning, exploitation, or unauthorized access on its own — all data comes from Shodan's existing index, and any on-demand scan requests are executed by Shodan's own infrastructure against targets you submit. You are responsible for ensuring you have authorization to query, monitor, or request scans of any target you use with this tool, and for complying with Shodan's Terms of Service and all applicable laws.

There aren't any published security advisories