A key requirement under UK law is
unauthorised access.
If someone explicitly asks you to hack their systems (and they have permission themselves), or if you want to do pentesting and hardening or your own systems, you should be fine.
The grey area here is how likely it is that someone would buy this tool for legitimate security analysis.
Most people wouldn't, which puts it on a slippery slope. A good defending lawyer should be able to make a good case for genuine legitimate use, but of course that's still going to leave some risk, not to mention a lot of stress and inconvenience before a case even gets to trial.