Terms of Service
Effective date: 14 July 2026
These terms govern your use of novahunting.ai (the "Site") and the free tools it provides — the NOVA rule playground and the skill scanner (together, the "Services"). The Site is operated by SecurityBreak Pty Ltd ("SecurityBreak", "we", "us"). By using the Site or the Services you agree to these terms; if you do not agree, please do not use them.
1. The Services
The Services are free, no-account tools for experimenting with the open-source NOVA framework: writing detection rules, scanning prompts against them, and scanning AI agent skills for risky patterns. The NOVA framework itself is distributed separately under its own open-source license on GitHub; these terms do not modify that license. The NovaHunting commercial platform is a separate product offered by SecurityBreak under its own agreement.
2. Acceptable use
- Use the Services only for lawful purposes.
- Do not attempt to disrupt the Services, circumvent rate limits or bot protection, or gain unauthorized access to the infrastructure behind them.
- Do not submit content you do not have the right to share, or content that is unlawful.
- Testing adversarial prompts and malicious skill samples inside the Services' own sandbox is exactly what they are for — but do not use the Services to attack third-party systems.
We may throttle, suspend or block access (for example via rate limits) to keep the Services available for everyone.
3. Your submissions and research use
When you run a scan, the content you submit (detection rules, prompts, skill files or repository references) and the scan results are retained by us and used for security research and to improve detection quality, as described in the Privacy Policy. You grant SecurityBreak a worldwide, royalty-free license to store, reproduce and analyze submitted content for those purposes. Do not submit personal, confidential or proprietary information.
Skill scanner results are public by default. Scanned skills, their names, descriptions, sources and verdicts appear in a public feed with permanent links, unless you select the "Private scan" option — in which case the result is unlisted: excluded from the public feed but accessible via its permanent link, and still retained under these terms. A privately scanned skill becomes public if the same skill is later scanned without the private option. Only submit skills you are comfortable seeing published or stored.
4. No warranty
The Services and their results are provided "as is", without warranty of any kind. Detection verdicts — including "clean" or "malicious" labels — are automated assessments that can be wrong in both directions. They are not professional security advice, and you should not rely on them as the sole basis for a security decision.
5. Limitation of liability
To the maximum extent permitted by law, SecurityBreak will not be liable for any indirect, incidental, special or consequential damages, or any loss of data, profits or business, arising from your use of the Site or the Services. Nothing in these terms excludes rights that cannot be excluded under applicable law, including the Australian Consumer Law.
6. Third-party services
The Site relies on third parties — including Cloudflare (hosting, bot protection), GitHub (repository fetching for skill scans) and asciinema (the demo player) — whose own terms govern their services.
7. Changes
We may update these terms from time to time. The effective date above reflects the latest revision; continued use of the Services after a change constitutes acceptance.
8. Governing law and contact
These terms are governed by the laws of Australia. Questions about these terms can be directed to SecurityBreak via securitybreak.io.
