https://github.com/NousResearch/hermes-agent.git
· scanned 2026-05-17 02:56 UTC (12 hours, 25 minutes ago)
· 10 languages
914 findings (102 legacy + 812 scanner) 7/10 scanners ran 86th percentile · Python · huge (>500K LoC) Scanner says 69 (higher by 17)
Last scanned 12 hours, 25 minutes ago · v1 · 914 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 910 of 914 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
hermes_cli/web_server.py:2596
authlegacy
hermes_cli/web_server.py:2539
authlegacy
plugins/kanban/dashboard/plugin_api.py:470
authlegacy
plugins/kanban/dashboard/plugin_api.py:583
authlegacy
hermes_cli/web_server.py:2569
authlegacy
hermes_cli/web_server.py:2578
authlegacy
hermes_cli/web_server.py:2587
authlegacy
plugins/kanban/dashboard/plugin_api.py:759
authlegacy
plugins/kanban/dashboard/plugin_api.py:1005
authlegacy
hermes_cli/web_server.py:2560
authlegacy
hermes_cli/codex_runtime_switch.py:185
injectionlegacy
acp_adapter/tools.py:804
injectionlegacy
optional-skills/mcp/fastmcp/templates/database_server.py:68
injectionlegacy
gateway/platforms/feishu.py:4756
path_traversallegacy
agent/google_oauth.py:554
path_traversallegacy
agent/google_code_assist.py:157
path_traversallegacy
gateway/platforms/api_server.py:1218
llm_injectionlegacy
hermes_cli/copilot_auth.py:16
credential_exposurelegacy
agent/credential_sources.py:10
credential_exposurelegacy
agent/auxiliary_client.py:3167
credential_exposurelegacy
plugins/platforms/google_chat/oauth.py:369
credential_exposurelegacy
plugins/google_meet/node/cli.py:73
credential_exposurelegacy
hermes_cli/webhook.py:179
credential_exposurelegacy
agent/anthropic_adapter.py:827
ssrflegacy
agent/account_usage.py:116
ssrflegacy
acp_adapter/server.py:141
ssrflegacy
optional-skills/research/darwinian-evolver/scripts/show_snapshot.py:36
resource_exhaustionlegacy
docker-compose.yml:57
dockerlegacy
docker-compose.yml:24
dockerlegacy
Dockerfile:101
dockerlegacy
gateway/session.py:302
llm_injectionlegacy
gateway/run.py:3162
integritysync-io-in-asyncperformance
gateway/run.py:16754
integritysync-io-in-asyncperformance
gateway/run.py:16763
integritysync-io-in-asyncperformance
hermes_cli/web_server.py:2313
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4223
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1500
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2596
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:798
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2815
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2447
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1543
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1228
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1283
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1481
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2800
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:583
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:759
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:785
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:829
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1460
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2548
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2710
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:520
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1389
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2746
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2569
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4198
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4186
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4158
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4210
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4261
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1096
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1005
authowaspauth.fastapi.unauth_mutation
plugins/hermes-achievements/dashboard/plugin_api.py:1037
authowaspauth.fastapi.unauth_mutation
plugins/hermes-achievements/dashboard/plugin_api.py:1042
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:716
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2578
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1242
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1049
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1043
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2247
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2285
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1249
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1510
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2587
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:731
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4241
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:3893
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1218
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2877
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2939
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1189
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2560
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2844
authowaspauth.fastapi.unauth_mutation
tools/skills_guard.py:294
owaspeval_used
hermes_cli/tips.py:306
owaspexec_used
skills/red-teaming/godmode/scripts/auto_jailbreak.py:52
owaspexec_used
skills/red-teaming/godmode/scripts/load_godmode.py:29
owaspexec_used
tools/approval.py:358
owaspexec_used
tools/skills_guard.py:297
owaspexec_used
hermes_cli/web_server.py:1228
authlegacy
hermes_cli/web_server.py:2313
authlegacy
hermes_cli/web_server.py:1543
authlegacy
hermes_cli/web_server.py:2447
authlegacy
hermes_cli/web_server.py:2533
authlegacy
hermes_cli/web_server.py:2539
authlegacy
hermes_cli/web_server.py:1511
authlegacy
hermes_cli/web_server.py:1242
authlegacy
hermes_cli/web_server.py:2247
authlegacy
hermes_cli/web_server.py:2285
authlegacy
agent/auxiliary_client.py:253
error_handlinglegacy
agent/anthropic_adapter.py:308
error_handlinglegacy
acp_adapter/tools.py:192
error_handlinglegacy
ui-tui/src/app/slash/commands/core.ts:108
error_handlinglegacy
ui-tui/src/app/createGatewayEventHandler.ts:136
error_handlinglegacy
scripts/whatsapp-bridge/bridge.js:627
error_handlinglegacy
tools/environments/docker.py:638
injectionlegacy
hermes_cli/tools_config.py:651
injectionlegacy
tools/transcription_tools.py:518
injectionlegacy
optional-skills/research/darwinian-evolver/scripts/show_snapshot.py:36
deserializationlegacy
hermes_cli/main.py:6274
path_traversallegacy
scripts/install_psutil_android.py:86
path_traversallegacy
agent/curator_backup.py:613
path_traversallegacy
optional-skills/research/domain-intel/scripts/domain_intel.py:94
cryptolegacy
hermes_cli/commands.py:279
redoslegacy
gateway/platforms/yuanbao.py:604
redoslegacy
agent/redact.py:180
redoslegacy
trajectory_compressor.py:1000
log_injectionlegacy
hermes_cli/web_server.py:2942
resource_exhaustionlegacy
gateway/platforms/wecom_callback.py:313
resource_exhaustionlegacy
agent/curator.py:652
resource_exhaustionlegacy
hermes_cli/config.py:1177
qualitylegacy
hermes_cli/main.py:82
qualitylegacy
hermes_cli/_parser.py:171
qualitylegacy
hermes_cli/tips.py:74
qualitylegacy
gateway/platforms/telegram.py:721
qualitylegacy
plugins/platforms/line/plugin.yaml:35
qualitylegacy
gateway/platforms/wecom_callback.py:3
qualitylegacy
gateway/platforms/webhook.py:57
qualitylegacy
hermes_cli/doctor.py:825
qualitylegacy
hermes_cli/setup.py:529
qualitylegacy
hermes_cli/model_switch.py:1316
qualitylegacy
hermes_cli/models.py:104
qualitylegacy
agent/credential_sources.py:7
qualitylegacy
docker-compose.yml:57
dockerlegacy
docker-compose.yml:24
dockerlegacy
Dockerfile:83
dockerlegacy
web/src/lib/api.ts:6
qualitylegacy
.well-known/security.txt
qualitylegacy
plugins/memory/hindsight/__init__.py:678
dependencylegacy
hermes_cli/memory_setup.py:108
dependencylegacy
hermes_cli/uninstall.py:669
dependencylegacy
README.zh-CN.md:34
dependencylegacy
README.md:36
dependencylegacy
plugins/memory/byterover/plugin.yaml:6
dependencylegacy
plugins/memory/byterover/__init__.py:10
dependencylegacy
plugins/memory/byterover/README.md:9
dependencylegacy
optional-skills/devops/cli/references/cli-reference.md:6
dependencylegacy
optional-skills/devops/cli/references/authentication.md:6
dependencylegacy
.github/ISSUE_TEMPLATE/setup_help.yml:35
dependencylegacy
.github/workflows/skills-index.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy-site.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nix-lockfile-fix.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/upload_to_pypi.yml
supply-chaingithub-actionsleast-privilege
cli.py:8046
owaspsubprocess_shell_true
hermes_cli/tools_config.py:651
owaspsubprocess_shell_true
tools/environments/docker.py:638
owaspsubprocess_shell_true
tools/transcription_tools.py:518
owaspsubprocess_shell_true
tui_gateway/server.py:4594
owaspsubprocess_shell_true
.dockerignore
dockerlegacy
docker-compose.yml:24
dockerlegacy
docker-compose.yml:24
dockerlegacy
agent/anthropic_adapter.py
qualitylegacy
Dockerfile:3
supply-chaindockerpinned-dependencies
Showing first 300 of 910. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/babdf5bb-90da-4ecd-a31d-8963b056e767/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/babdf5bb-90da-4ecd-a31d-8963b056e767/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.