https://github.com/NousResearch/hermes-agent.git
· scanned 2026-05-17 02:56 UTC (13 hours, 22 minutes ago)
· 10 languages
914 findings (102 legacy + 812 scanner) 7/10 scanners ran 86th percentile · Python · huge (>500K LoC) Scanner says 69 (higher by 17)
Last scanned 13 hours, 22 minutes ago · v1 · 914 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 812 of 914 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
gateway/run.py:3162
integritysync-io-in-asyncperformance
gateway/run.py:16754
integritysync-io-in-asyncperformance
gateway/run.py:16763
integritysync-io-in-asyncperformance
hermes_cli/web_server.py:2313
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4223
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1500
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2596
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:798
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2815
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2447
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1543
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1228
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1283
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1481
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2800
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:583
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:759
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:785
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:829
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1460
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2548
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2710
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:520
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1389
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2746
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2569
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4198
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4186
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4158
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4210
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4261
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1096
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1005
authowaspauth.fastapi.unauth_mutation
plugins/hermes-achievements/dashboard/plugin_api.py:1037
authowaspauth.fastapi.unauth_mutation
plugins/hermes-achievements/dashboard/plugin_api.py:1042
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:716
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2578
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1242
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1049
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1043
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2247
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2285
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1249
authowaspauth.fastapi.unauth_mutation
plugins/kanban/dashboard/plugin_api.py:1510
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2587
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:731
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:4241
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:3893
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1218
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2877
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2939
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:1189
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2560
authowaspauth.fastapi.unauth_mutation
hermes_cli/web_server.py:2844
authowaspauth.fastapi.unauth_mutation
tools/skills_guard.py:294
owaspeval_used
hermes_cli/tips.py:306
owaspexec_used
skills/red-teaming/godmode/scripts/auto_jailbreak.py:52
owaspexec_used
skills/red-teaming/godmode/scripts/load_godmode.py:29
owaspexec_used
tools/approval.py:358
owaspexec_used
tools/skills_guard.py:297
owaspexec_used
.github/workflows/skills-index.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy-site.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nix-lockfile-fix.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/upload_to_pypi.yml
supply-chaingithub-actionsleast-privilege
cli.py:8046
owaspsubprocess_shell_true
hermes_cli/tools_config.py:651
owaspsubprocess_shell_true
tools/environments/docker.py:638
owaspsubprocess_shell_true
tools/transcription_tools.py:518
owaspsubprocess_shell_true
tui_gateway/server.py:4594
owaspsubprocess_shell_true
Dockerfile:3
supply-chaindockerpinned-dependencies
package.json
supply-chainnpminstall-scripts
cli.py:12797
dead-code
hermes_state.py:2237
dead-code
scripts/build_skills_index.py:66
dead-code
tui_gateway/server.py:438
dead-code
utils.py:285
dead-code
utils.py:274
dead-code
agent/google_oauth.py:455
dead-code
tui_gateway/server.py:5933
dead-code
cli.py:11815
dead-code
agent/google_oauth.py:748
dead-code
trajectory_compressor.py:948
dead-code
cli.py:13531
dead-code
agent/anthropic_adapter.py:757
dead-code
agent/lsp/cli.py:22
dead-code
tui_gateway/server.py:3014
dead-code
cli.py:8174
dead-code
agent/lsp/cli.py:70
dead-code
agent/video_gen_provider.py:213
dead-code
agent/video_gen_provider.py:233
dead-code
agent/trajectory.py:30
dead-code
tui_gateway/server.py:1660
dead-code
cli.py:13511
dead-code
cli.py:10939
dead-code
website/scripts/generate-skill-docs.py:239
dead-code
Showing first 300 of 812. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/babdf5bb-90da-4ecd-a31d-8963b056e767/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/babdf5bb-90da-4ecd-a31d-8963b056e767/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.