Recat
0xtbug/Recat
Local workspace for reviewing security findings reported by Hermes and other agents
Recat is a local workspace for security findings. It lets you review findings reported by Hermes or other agents, inspect evidence and export reports across web, smart contract and other assets.
What Recat does
Recat reads a folder of security findings and presents them in a local web app. Each finding sits in project-name/bug/finding-name/ with a finding.json, a README.md and an optional poc/ folder. Fields include asset_type (web, smart_contract or other), status (candidate, confirmed or false_positive) and severity (critical, high, medium, low or info). The dashboard shows severity, status, activity and asset coverage, with search and filters by project, category, vulnerability class and status, plus an evidence viewer, JSON exports and project ZIP downloads.
Recat rescans the project folders every five seconds, displays reported results and preserves the original records. A reporting skill, recat-findings, lets an agent write findings straight into the source folder. The README lists install paths for Codex, Claude Code and Hermes, where the personal Hermes path is ~/.hermes/skills/recat-findings/SKILL.md and the skill is invoked with /recat-findings. Access can be protected with a password, and a censored view is available.
Key features
- Dashboard of severity, status, activity and asset coverage
- Search and filters by project, category, vulnerability class and status
- Evidence viewer, JSON exports and project ZIP downloads
- Findings read from a folder and rescanned every five seconds
- Password access and a censored view
- recat-findings skill for Codex, Claude Code and Hermes
When to use it
- Triaging findings that a Hermes agent reports across web and smart contract targets
- Marking findings as candidate, confirmed or false positive
- Exporting evidence and project archives for a report
Who it is for: Security researchers who use AI agents to find vulnerabilities and want one local place to review and export the results.
How it fits with Hermes Agent
Hermes is one of three agents the reporting skill supports, alongside Codex and Claude Code, and the skill installs into ~/.hermes/skills.
How to install Recat
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
bun install
bun run devRequirements: Bun, a RECAT_PASSWORD set in .env, and a running server with access to the findings folder
FAQ
What is Recat?
Recat is a local web workspace for security findings. It shows findings written by agents, lets you inspect evidence and exports reports.
Does Recat work with Hermes Agent?
Yes. Its recat-findings skill can be installed at ~/.hermes/skills/recat-findings/SKILL.md and invoked with /recat-findings, and the agent writes findings into the source folder.
How do I install Recat?
Create .env from .env.example with a RECAT_PASSWORD, then run bun install and bun run dev. For production, run bun run build and bun run start, which binds to 127.0.0.1:5173 unless PORT is set.
Similar security for Hermes Agent
All securityHermes plugin that has a second-lab model review each task before a subagent starts writing code
intentframe IntentFrame for Hermes AgentIntentFrame security plugin that checks Hermes terminal, code, file and cron tool calls against policy
mauricemohr88-debug Hermes Plugin GuardStatic security scanner for Hermes Agent plugins that never imports or runs the plugin code
wnstify Hermes Agent Hardening PatternsHardened Docker Compose and SSH sandbox patterns for self-hosting Hermes Agent with Honcho
aibuild-lab Skills GuardThreat scanner and trust matrix for AI skill files, ported from Hermes Agent's skills_guard
jooray hermes-firewallPrompt-injection gate plugin that scans web, MCP, email and image content before Hermes Agent sees it
Related guides: How to run Hermes Agent securely