以下条文对 Hx0 HawkEye 的 Chrome 版与 Firefox 版具有同等效力;因浏览器扩展 API 不同而产生的实现差异(例如侧栏托管方式、被动抓包调试提示、文件选择窗口交互等)不改变您在数据、合规与安全方面的义务,也不改变社区版、试用版、专业版在法律意义上的边界。
0. 扩展内强制确认(与正常使用的关系)
- 为落实知情同意与版本可追溯性,本扩展在浏览器工具栏弹窗中提供协议摘要滚动区;您须将摘要滚动至底部后,方可勾选确认框并点击「同意并继续使用」。
- 未完成上述步骤前,抓包、重放、悬浮球、侧栏等主要能力不予开放(与未同意状态一致)。
- 当我们更新协议实质内容时,可能要求您重新完成一次确认;届时请以弹窗提示为准。
说明:本页面为完整文本,便于存档、打印与复查;扩展内摘要旨在突出关键义务。若摘要与本页存在表述差异,以更新日期较新的完整文本为准。
1. 生效与同意
- 当你安装、启用或继续使用本工具,即表示你已阅读并同意本协议与隐私条款(含摘要与完整版)。
- 若你不同意,请立即停止使用并卸载本工具。
- 本协议可根据产品功能、授权策略与法律要求更新;更新后请留意扩展内提示与本页面版本说明。
2. 合法合规与授权边界(含中国大陆用户提示)
- 你必须遵守所在地与目标系统所在地的法律法规、行业规范及所在组织的授权与制度。
- 仅可在你拥有所有权或已获得明确书面/制度性授权的系统、网络、应用和数据范围内使用本工具。
- 社区版、试用版、专业版只是产品功能层级,并不会扩大你对目标系统的测试权限。
- 严禁将本工具用于未授权入侵、非法获取或破坏数据、干扰网络与系统正常运行、传播恶意程序、诈骗、洗钱、绕过安全防护等违法活动。
下列法律名称仅作合规主题提示,不构成法律意见或穷尽列举。具体适用以有权机关解释与司法实践为准。
- 《中华人民共和国网络安全法》:网络运行安全、网络信息安全、关键信息基础设施保护、网络日志留存与配合义务等相关要求。
- 《中华人民共和国数据安全法》:数据处理活动中的数据分类分级、重要数据与核心数据保护、风险监测与应急处置、数据出境安全评估等制度框架。
- 《中华人民共和国个人信息保护法》:处理个人信息应遵循合法、正当、必要和诚信原则,履行告知—同意、最小必要、安全保障、跨境提供条件、响应个人权利请求等要求。
- 如涉及关键信息基础设施运营者、重要数据、个人信息出境、等保测评等场景,你应自行完成合规评估、备案/审批与合同安排。
重要:任何越权测试、未授权攻击及其后果,均由使用者自行承担法律责任。
3. 许可、版本与反盗版
- 本产品当前包含社区版、首次安装 30 分钟专业版试用、以及通过离线激活码和/或在线会员启用的专业版(v1.0.6);具体可用功能以软件界面与用户手册为准;授权开通方式见用户手册 §13(在线/离线可组合使用,不属于社区版与专业版的功能对比表项)。
- 社区版开放范围:智能代理分流器、敏感信息匹配(含内置规则、自定义正则、关键词库、批量导入导出与一键清空)及列表全量深度搜索无需专业版权益或激活即可使用;启用这些能力仍不扩大您对任何目标系统的授权范围。
- 在线会员:开通或续费时可能连接第三方支付/会员服务以完成订单;联网时会同步会员状态并缓存到本机。您的用户 ID用于识别权益,请妥善保存;除您主动发起同步、开通或客服协助流程外,扩展不会上传抓包正文。
- 离线激活:激活码校验在本机本地完成,不要求持续连接外部授权服务器。
- 社区版下点击专业能力入口时,可能出现功能说明、升级提示、激活窗口或跳转到获取激活码的外部页面;这些交互仅用于版本引导,不构成额外授权,也不改变你对目标系统的使用边界。
- 本工具及其代码、界面、图标、文档、规则等受著作权法及相关法律保护。
- 未经书面许可,禁止复制、转售、出租、分发、去除版权标识、反编译、逆向或变相盗版传播。
- 除非获得授权,不得用于构建或提供与本工具实质性竞争的商业产品或服务。
4. 数据处理与隐私说明
- 本地优先:设置与大部分工作数据默认保存在本地浏览器环境中(如规则、偏好、历史记录、抓包条目、重放草稿、测试页签、AI 技能文件、AI 任务日志与报告等)。
- 鹰眼浏览器自动化 MCP(VIP / 专业版):仅在专业权限有效、您主动开启开关并运行本地 MCP Server 时,您配置的第三方 Agent 才能操作当前绑定标签页并读取鹰眼工具返回的数据。服务仅监听本机回环地址;但 Agent 仍可能根据其自身配置把工具结果发送至模型服务。请仅连接可信 MCP Host,并在完成后关闭开关。
- 激活、试用与设备标识:为校验授权、防误删与维持试用状态,相关信息保存在本机浏览器环境中;设备标识由当前浏览器环境在本地生成,用于与激活码对应。
- 在线会员与用户 ID:在线开通、续费或状态同步时,可能向会员/支付服务提供用户 ID、订单相关信息等必要信息;会员状态会缓存于本机以便离线使用。请勿将用户 ID 泄露给不可信第三方。
- 本地离线激活校验:在本地粘贴离线激活码、查看授权详情、显示剩余时间等行为,默认不要求连接外部授权服务器;除非你主动点击外部购买/联系链接、发起在线会员流程或自行配置第三方 AI 服务,否则这些本地授权步骤不会自动把抓包内容上传到远端。
- 页面脚本库:您新建、导入或 AI 生成的脚本保存在本机;仅在您执行注入或启用「匹配域名自动注入」时,扩展向匹配规则的网页标签注入脚本代码。脚本通过
GM_xmlhttpRequest / GM_hx0CallTool 发起的跨域或后台请求经扩展转发,不会因此默认将整份脚本库上传至 Hx0 服务器。
- AI 技能(Skills):您导入、编辑或 AI 生成的技能文档保存在本机。高级设置中未启用的 Skill 不会被 AI 任务或 Agent 调用;Agent 新会话的 Skills 默认关闭,还需您点击当前会话的 Skills 开关后,才会在全局已启用范围内按目标适时选择。只有实际被选中的技能内容才会随任务上下文发送至您配置的 AI 服务端点,不会默认上传至 Hx0 自有服务器。
- AI 生成技能:您在「AI 生成技能」中输入的描述、生成过程中的 prompt 片段,以及保存前的编辑内容,在点击生成时会发送至您配置的 AI 服务端点;保存后的 Skill(含写入内置库的 AI 生成子模块)仍驻留本机,处理方式与导入技能相同。
- AI 任务报告数据:任务执行日志、测试胶囊、分析报告(含漏洞清单、
request_response_evidence 等结构化字段)默认保存在本机;下载或导出报告时由您自行保管、脱敏与分享。
- 抓包数据责任:请求/响应可能包含 Cookie、Token、账号、个人信息、商业秘密等;你需自行负责保管、脱敏、导出、留存期限与销毁,并满足监管对日志与证据的要求。
- 敏感匹配与全量深度搜索:对已捕获请求/响应的匹配和检索默认在本机完成;自定义正则、关键词及开关保存在本地浏览器环境,不会因启用该功能而默认上传至 Hx0 服务器。完整正文检索会增加本机资源消耗,也可能让更多敏感片段出现在本地搜索结果中。
- 智能代理分流:上游地址、站点规则与运行状态默认保存在本机。启用后,命中规则的浏览器流量会被发送至您配置的 Burp、Yakit 或其他上游代理;该代理及其证书、日志、存储和转发行为由您负责评估。HTTPS 解密前请仅信任您控制的根证书,完成后及时关闭不再需要的分流。
- AI 调用:当你主动触发 AI 分析、AI 结果分析、AI 生成用例、AI 生成技能或 AI 任务台时,相关文本会发送到你配置的 AI 服务端点;该服务的数据留存、审计、跨境传输与合规策略由对应服务商与你之间的约定管辖。
- AI 自动脱敏:支持的 AI 流程默认在发送前遮盖常见 Cookie、Authorization、Token、密码等字段,但自动识别不能保证覆盖所有敏感数据。若你为理解登录态或鉴权上下文而在设置中关闭此功能,相关内容将按原文发送至你配置的 AI 服务端点;请仅在已授权环境中使用并自行承担外传风险。
- 最小化原则:建议仅提交必要片段进行分析,避免上传整包敏感数据。
- 第三方风险:你应自行评估并遵守第三方 AI、代理网关、会员/支付或模型平台的协议与合规要求。
- 未成年人:若你为未成年人,请在监护人指导下阅读本政策并取得同意后使用。
- 多浏览器安装:若你同时在 Chrome 与 Firefox 中安装本扩展,各自在对应浏览器配置下形成独立的本地存储、历史记录、用户 ID/机器码环境;数据不会跨浏览器自动合并。
5. 安全使用建议
- 优先在测试/预发环境使用;生产环境操作前请完成审批、备份与风险评估。
- 对导出报告、抓包数据、截图和 AI 输出结果进行权限控制,避免二次泄露。
- 涉及个人信息或商业敏感信息时,请遵循最小授权、最小上传、最小留存原则。
- 在社区版或专业版中使用任何导出、批量、AI 或暗链检测能力前,都应先确认目标系统和数据范围在你的授权之内。
6. 免责声明与责任限制
- 本工具按“现状”提供,不承诺适配所有站点、浏览器实现、WAF 场景、代理链路或第三方服务,也不承诺绝对无缺陷或持续可用。
- 社区版、试用版、专业版之间的入口显隐、锁定态、升级提示、功能说明弹窗与激活窗口仅属于产品交互,不构成对任何目标系统、数据或第三方服务的使用保证。
- 因你自身配置、网络环境、第三方服务、越权使用、错误操作、导出泄露或对 AI 服务配置不当造成的损失,由你自行承担。
- 在法律允许范围内,本产品提供方不对任何间接损失、数据损失、业务中断、机会损失或行政处罚承担责任。
7. 联系与反馈
如需商业授权、企业支持、漏洞与 Bug 反馈、功能建议或合规咨询,请联系 Hx0战队。推荐渠道:
反馈问题时请尽量说明浏览器与扩展版本、授权状态、复现步骤与环境,便于我们排查与跟进。
These terms apply equally to the Chrome and Firefox distributions of Hx0 HawkEye. Differences caused by browser-extension APIs (sidebar hosting, passive-capture banners, helper windows for file pickers, and similar UX details) do not change your obligations, nor do they change the legal meaning of Community, trial, or Pro gating.
0. In-extension mandatory acknowledgment
- To document informed consent and version traceability, the extension popup shows a scrollable summary. You must scroll it to the end, then check the box and choose Agree and continue.
- Until that is completed, core features such as capture, replay, floating-ball entry, and the sidebar workflow remain unavailable.
- When we materially update these terms, we may ask you to confirm again.
Note: This page is the full text for archival reading. The in-product summary highlights key obligations only. If wording differs, prefer the newer dated full text.
1. Acceptance
- By installing, enabling, or continuing to use this tool, you agree to these Terms and Privacy clauses (summary and full text).
- If you do not agree, stop using and uninstall the tool immediately.
- These terms may be updated over time to reflect product, licensing, and legal changes.
2. Lawful use and authorization boundaries
- You must comply with laws where you and the target systems reside, plus relevant industry rules and your organization’s policies.
- Use only within systems, networks, applications, and data you own or are explicitly authorized to test.
- Community, trial, and Pro are product tiers only; they do not expand your authorization to test any target.
- No unauthorized intrusion, exfiltration, disruption, malware, fraud, or abuse.
The following statutes are named for compliance awareness only, not as legal advice or an exhaustive list.
- Cybersecurity Law of the PRC — network operations security, network information security, critical information infrastructure, logging, and cooperation duties.
- Data Security Law of the PRC — data processing governance, important/core data, risk monitoring, incident response, and cross-border frameworks.
- Personal Information Protection Law of the PRC — lawful basis, notice and consent, minimization, security measures, cross-border conditions, and data-subject rights.
- If you operate in regulated contexts (CII operators, important data, PI export, classified compliance regimes), perform your own assessments and approvals.
Important: You are solely responsible for unauthorized testing and its legal consequences.
3. Licensing, editions, and anti-piracy
- The current product lineup includes a Community Edition, an initial 30-minute full Pro trial, and a Pro edition enabled by offline activation code and/or online membership (v1.0.6). Feature boundaries follow the in-product UI and user manual; how to activate is documented in manual §13 and is not a Community-vs-Pro feature-comparison row. Online and offline activation may be combined.
- Community availability: Smart Proxy Router, sensitive matching (built-ins, custom regex, keyword libraries, batch import/export, and clear-all), and full deep search require no Pro entitlement or activation. Availability never expands your authorization over a target system.
- Online membership: checkout or renewal may connect to third-party payment/membership services; when online, status syncs and is cached locally. Your User ID identifies entitlements—keep it safe. Capture bodies are not uploaded except when you initiate sync, checkout, or other flows you start.
- Offline activation: code verification runs locally on this device without a permanently connected licensing server.
- In Community mode, clicking Pro entries may show feature guidance, upsell prompts, activation dialogs, or an external “get activation code” page. These flows are edition guidance only and do not grant extra authorization over any target system.
- The software and related assets are protected by copyright and applicable laws.
- No unauthorized copying, resale, redistribution, reverse engineering, or removal of notices.
- No competing commercial use without explicit permission.
4. Data and privacy
- Local-first: settings and most runtime data stay in the local browser environment (rules, preferences, history, captured packets, replay drafts, test tabs, AI Skill files, AI Task logs and reports, and similar workspace data).
- HawkEye Browser Automation MCP (VIP / Pro): only while professional access is active, after you enable the switch and run the local MCP Server, can your configured third-party agent operate the bound tab and read data returned by HawkEye tools. The server listens only on the local loopback interface, but the agent may still send tool results to its configured model service. Connect only trusted MCP hosts and turn the switch off when finished.
- Activation, trial, and device identifier: to preserve licensing state and reduce accidental resets, related information is stored in the local browser environment. The device identifier is generated locally for your current browser profile and pairs with activation codes.
- Online membership & User ID: online checkout, renewal, or status sync may send necessary information such as User ID and order-related metadata to membership/payment services; cached status may be kept locally for offline use. Do not share your User ID with untrusted parties.
- Local offline activation checks: pasting an offline code, opening license details, and displaying time remaining do not normally require an external licensing server. Unless you actively open an external purchase/contact link, start an online membership flow, or send content to your configured AI provider, those local licensing steps do not automatically upload captured traffic.
- Page script library: scripts you create, import, or generate with AI stay on-device. Injection runs only when you manually inject or enable matched-domain auto-injection on tabs that match the script rules. Cross-origin or background calls via
GM_xmlhttpRequest / GM_hx0CallTool are proxied through the extension and do not, by default, upload your entire script library to Hx0 servers.
- AI Skills: imported, edited, or AI-generated skill documents stay on-device. A Skill disabled in Advanced Settings cannot be called by AI Tasks or Agent. Skills are also off in every new Agent conversation until you click that conversation's Skills control; after that, relevance matching is still limited to the globally enabled allowlist. Only content actually selected by these gates is sent with task context to your configured AI endpoint, not by default to Hx0-operated servers.
- AI Generate Skill: descriptions you enter, prompt fragments during generation, and pre-save edits are sent to your configured AI endpoint when you start generation. Saved Skills—including AI-generated built-in sub-modules—remain on-device and are handled like imported skills.
- AI Task report data: execution logs, test capsules, and analysis reports (including vulnerability inventory and
request_response_evidence) stay on-device by default; you control retention and sharing when downloading or exporting reports.
- Captured traffic may include secrets and personal data; you are responsible for protection, minimization, retention, export control, and lawful destruction.
- Sensitive matching and full deep search: matching captured requests/responses runs locally by default. Custom regex, keywords, and switches remain in the browser profile and are not uploaded to Hx0 servers merely by enabling these features. Full-body search consumes more local resources and may expose additional sensitive snippets in local search results.
- Smart Proxy Router: upstream addresses, site rules, and runtime state are stored locally by default. When enabled, matching browser traffic is sent to the Burp, Yakit, or other upstream proxy you configure. You are responsible for that proxy's certificates, logs, storage, and onward forwarding. Trust only a root certificate you control and disable routing when no longer needed.
- AI requests: when you trigger AI analysis, AI result analysis, AI case generation, AI Generate Skill, or the AI Task desk, selected content is sent to your configured endpoint/provider, including any cross-border implications under that provider’s terms.
- Automatic AI redaction: supported AI flows mask common Cookie, Authorization, token, and password fields before sending by default, but automated detection cannot guarantee coverage of every secret. If you disable this option in Settings to preserve authentication context, relevant content is sent as-is to your configured AI endpoint. Use this only in authorized environments and accept the disclosure risk.
- Data minimization: send only the minimum necessary content, with redaction where needed.
- Third-party risk: assess and comply with agreements and compliance requirements of any AI provider, proxy gateway, membership/payment, or model platform you choose to use.
- Minors: if you are a minor, use this tool only with guardian guidance and consent.
- Multiple browsers: installing in both Chrome and Firefox creates separate local storage, capture history, User ID/machine-ID contexts per browser profile; data is not merged automatically across browsers.
5. Safe-use practices
- Prefer staging or test environments; complete approvals, backups, and risk review before touching production.
- Control access to exports, captures, screenshots, and AI-generated outputs to avoid secondary disclosure.
- For personal or commercially sensitive data, follow least-privilege, least-upload, and least-retention principles.
- Before using export, batch, AI, or dark-link features in any edition, confirm the target system and data scope are within your authorization.
6. Disclaimer and limits of liability
- This tool is provided on an “as is” basis. We do not warrant compatibility with every site, browser behavior, WAF workflow, proxy chain, or third-party service, nor uninterrupted or error-free operation.
- Edition-specific UI such as hidden entries, locked states, tooltips, feature guidance, or activation windows is product interaction only and does not guarantee access, results, or suitability for any target system or third-party service.
- You assume risks arising from your configuration, network environment, third-party services, misuse, operator error, export leakage, or insecure AI-provider settings.
- To the extent permitted by law, the provider is not liable for indirect losses, data loss, business interruption, lost opportunities, or regulatory penalties arising from your use.
7. Contact
For commercial licensing, enterprise support, bug reports, feature requests, or compliance questions, please contact Team Hx0 (Hx0战队). Preferred channels:
When reporting issues, include browser version, extension version, license state, and reproduction steps where possible.