AppSec Recon Framework performs active TCP connections and HTTP requests.
Use it only against localhost, systems you own, or targets for which you have
explicit written authorization. Non-loopback scans require the
--acknowledge-authorization flag. That flag records intent; it does not grant
permission or replace an agreed scope of work.
The scanner applies bounded concurrency, target and job limits, response-size limits, request timeouts and a configurable delay. Do not remove those controls when testing shared infrastructure.
If you discover a vulnerability in the scanner itself, report it privately to the repository owner through GitHub. Do not include real credentials, internal reports, customer targets or unredacted scanner evidence in a public issue.