Intentions are very often a factor when it comes to law, and rightfully so. The problems come when you classify some category of software as "dangerous" by default. Software is special in that it can't be a "controlled substance". So everyone needs to have the tools to increase their security. That includes access to "offensive tools" to study what they do. A recent example was the Huggingface attack.
As I understand the hole shebang, the German law is about "does the court think you are `hacking` something?" -- this is against the law.
Yes, there was one German pentester that got sued, because he reported a BASE64 encoded, hardcoded authentication token in an application. Not that I would wish him anything like that and am ashamed by the outcome, I also recall that he might have tried to put pressure on the vendor by doing an interview with a blogger or so?
On the other hand, I do not know of any cases regarding publication of dual-use tools as OSS.