I don't think I've ever seen people gone after for the former, even when it's been abused by miscreants.
At least in the US, people already "go after" security researchers all the time (at least the companies not smart enough to realise just how much a well meaning email can save them).
If someone explicitly asks you to hack their systems (and they have permission themselves), or if you want to do pentesting and hardening or your own systems, you should be fine.
The grey area here is how likely it is that someone would buy this tool for legitimate security analysis.
Most people wouldn't, which puts it on a slippery slope. A good defending lawyer should be able to make a good case for genuine legitimate use, but of course that's still going to leave some risk, not to mention a lot of stress and inconvenience before a case even gets to trial.
Do you mind picking a non-trollish username and letting us rename it for you?