https://github.com/NousResearch/hermes-agent.git
· scanned 2026-05-17 02:56 UTC (13 hours, 26 minutes ago)
· 10 languages
914 findings (102 legacy + 812 scanner) 7/10 scanners ran 86th percentile · Python · huge (>500K LoC) Scanner says 69 (higher by 17)
Last scanned 13 hours, 26 minutes ago · v1 · 914 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 94 of 914 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
hermes_cli/web_server.py:1228
authlegacy
hermes_cli/web_server.py:2313
authlegacy
hermes_cli/web_server.py:1543
authlegacy
hermes_cli/web_server.py:2447
authlegacy
hermes_cli/web_server.py:2533
authlegacy
hermes_cli/web_server.py:2539
authlegacy
hermes_cli/web_server.py:1511
authlegacy
hermes_cli/web_server.py:1242
authlegacy
hermes_cli/web_server.py:2247
authlegacy
hermes_cli/web_server.py:2285
authlegacy
ui-tui/src/app/slash/commands/core.ts:108
error_handlinglegacy
ui-tui/src/app/createGatewayEventHandler.ts:136
error_handlinglegacy
scripts/whatsapp-bridge/bridge.js:627
error_handlinglegacy
tools/environments/docker.py:638
injectionlegacy
hermes_cli/tools_config.py:651
injectionlegacy
tools/transcription_tools.py:518
injectionlegacy
optional-skills/research/darwinian-evolver/scripts/show_snapshot.py:36
deserializationlegacy
hermes_cli/main.py:6274
path_traversallegacy
scripts/install_psutil_android.py:86
path_traversallegacy
agent/curator_backup.py:613
path_traversallegacy
optional-skills/research/domain-intel/scripts/domain_intel.py:94
cryptolegacy
hermes_cli/commands.py:279
redoslegacy
gateway/platforms/yuanbao.py:604
redoslegacy
agent/redact.py:180
redoslegacy
trajectory_compressor.py:1000
log_injectionlegacy
hermes_cli/web_server.py:2942
resource_exhaustionlegacy
gateway/platforms/wecom_callback.py:313
resource_exhaustionlegacy
agent/curator.py:652
resource_exhaustionlegacy
hermes_cli/config.py:1177
qualitylegacy
hermes_cli/main.py:82
qualitylegacy
hermes_cli/_parser.py:171
qualitylegacy
hermes_cli/tips.py:74
qualitylegacy
gateway/platforms/telegram.py:721
qualitylegacy
plugins/platforms/line/plugin.yaml:35
qualitylegacy
gateway/platforms/wecom_callback.py:3
qualitylegacy
gateway/platforms/webhook.py:57
qualitylegacy
hermes_cli/doctor.py:825
qualitylegacy
hermes_cli/setup.py:529
qualitylegacy
hermes_cli/model_switch.py:1316
qualitylegacy
hermes_cli/models.py:104
qualitylegacy
agent/credential_sources.py:7
qualitylegacy
docker-compose.yml:57
dockerlegacy
docker-compose.yml:24
dockerlegacy
.well-known/security.txt
qualitylegacy
plugins/memory/hindsight/__init__.py:678
dependencylegacy
hermes_cli/memory_setup.py:108
dependencylegacy
hermes_cli/uninstall.py:669
dependencylegacy
README.zh-CN.md:34
dependencylegacy
README.md:36
dependencylegacy
plugins/memory/byterover/plugin.yaml:6
dependencylegacy
plugins/memory/byterover/__init__.py:10
dependencylegacy
plugins/memory/byterover/README.md:9
dependencylegacy
optional-skills/devops/cli/references/cli-reference.md:6
dependencylegacy
optional-skills/devops/cli/references/authentication.md:6
dependencylegacy
.github/ISSUE_TEMPLATE/setup_help.yml:35
dependencylegacy
.github/workflows/skills-index.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy-site.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nix-lockfile-fix.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/upload_to_pypi.yml
supply-chaingithub-actionsleast-privilege
cli.py:8046
owaspsubprocess_shell_true
hermes_cli/tools_config.py:651
owaspsubprocess_shell_true
tools/environments/docker.py:638
owaspsubprocess_shell_true
tools/transcription_tools.py:518
owaspsubprocess_shell_true
tui_gateway/server.py:4594
owaspsubprocess_shell_true
This page is publicly accessible at:
https://repobility.com/scan/babdf5bb-90da-4ecd-a31d-8963b056e767/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/babdf5bb-90da-4ecd-a31d-8963b056e767/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.