ESP32 DoomsDay supports diagnostics, learning, and authorized security work. It does not turn someone else’s network or device into a valid target.
Use wireless-security features only on equipment and networks you own or have explicit permission to assess.
Active tests should remain visible through device indicators, screen state, and portal logs. Stop them when the session ends.
Apps receive only declared capabilities that a user grants. The runtime does not expose arbitrary pointers, GPIO, sockets, or raw files.
Wi-Fi, BLE, ADC2 sensing, packet monitoring, and accessory sessions must explicitly acquire and release shared resources.
Risk scores and scan heuristics are observations, not proof of compromise. Verify findings at the router or system of record.
The local device portal is intended for a trusted LAN or the device’s own hotspot. Do not expose it through router port forwarding. Before commercial release, portal-wide authentication and a physical confirmation policy should be part of the final threat-model review.