Before you start
- Check open issues
- One feature per PR
- Run tests:
pytest tests/ - Scanner additions need a real PoC or real-world precedent — no theoretical-only detectors
Workflow
Commit prefixes
PR checklist
-
pytest tests/passes - No hardcoded targets, API keys, or real domain names in code
- Scanner additions use
[CONFIRMED]/[POSSIBLE]/[INFORMATIONAL]confidence states - Methodology changes cite a real finding or public write-up