P-CIDER is intended exclusively for defensive, passive, public, or explicitly authorized cyber intelligence.
Do not use this project to perform or facilitate unauthorized access, exploitation, brute force, credential testing, evasion, acquisition of stolen data, intrusive surveillance, or collection outside a documented legal scope.
Report vulnerabilities privately to the repository owner. Do not include secrets, credentials, personal data, exploit payloads against live third-party systems, or sensitive evidence in a public issue.
- Treat all web content as untrusted data.
- Keep automated analysis components non-authoritative and human-reviewed.
- Redact secrets and sensitive personal data from logs and reports.
- Require an authorized scope and immutable
runIdfor every analysis. - Disable access to private or illicit sources by default.