Zyrexnn/Cybermes
Credits + grant $7OtherQuick Start • Architecture • Automated PDF Reports • Skills Layer • Discussions & Rules • Documentation • Release Notes
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
- Python86.5%
- Go4.5%
- TypeScript3.3%
- CSS1.8%
- JavaScript1.5%
- Shell0.9%
- MDX0.8%
- Handlebars0.7%
Placement
Every place and its price$7
$6.60 from converted credits; $0.40 granted by RepoRanker. Credits and grants are not card payments. This placement does not expire. Its rank holds until another repo spends more, and then this one moves down, never off. Taking the top of the board from here costs $11.
1 Review
Cybermes combines a large offensive-security knowledge base with Hermes Agent, more than 200 skill directories, native Go utilities, browser automation, and automated reporting. The original Go components cover stream filtering, secret detection, knowledge search, and report aggregation, with focused unit tests and race detection in CI. Python scripts generate HTML and PDF deliverables, while the diagnostic utility checks configuration, dependencies, directories, and tool availability. Linux, Windows, and Docker setup paths are documented, and the repository includes contribution guidance, a code of conduct, security reporting instructions, release history, and detailed third-party attribution. The skill validator and Python syntax checks also run successfully against the current tree.
The biggest issue is the authorization model. scope.yaml permits every target through a wildcard, enables dynamic overrides, and declares anything entered by the operator authorized. AGENTS.md repeats that assumption. A legal warning does not verify permission, especially for an autonomous framework that can run scanners and generate exploit proofs. The safe default should allow only localhost or explicit assets entered in a separate engagement file. Cybermes should reject targets outside that list, require confirmation before active testing, preserve an audit trail, and enforce rate and destructive-action limits in code. The “zero false positive” gate is also mainly an instruction for the model, not a deterministic framework control. Reports should pass a machine-enforced evidence schema before Cybermes calls a finding confirmed.
Packaging and claim accuracy need attention. The repository is roughly 384 MB because it vendors full tools and knowledge projects with several licenses, including Apache, GPL, MIT, and noncommercial Creative Commons material. The attribution work is useful, but separating upstream content into pinned downloads or submodules would reduce repository size and make updates easier to audit. Installation also pulls latest binaries and broadly versioned Python and npm packages without checksum verification, while several failures are ignored before setup prints a success message. A clean Docker build does not install every command advertised in the README, so CI should run tool-availability smoke tests and a complete assessment against the included mock application. Benchmarks should support the stated 70 to 85 percent token savings, and “zero-allocation” should be removed because smart_pipe allocates maps, slices, strings, and regular-expression results. Finally, the security policy lists version 1.5 as supported even though the current release is 2.1.0.
