Scope controls
Scanner requests are constrained to verified targets and do not follow off-scope domains.
Private, local, link-local, and metadata endpoints are blocked to prevent internal network abuse.
Production-safe checks
The built-in scanner packages focus on non-destructive observations and configuration checks rather than exploit payloads.
Concurrency and cooldown controls help prevent repeated scan starts from overwhelming a target or organization.