Hermes Atlas
Security & sandboxing · works with Hermes Agent

Recat

0xtbug/Recat

Local workspace for reviewing security findings reported by Hermes and other agents

In short

Recat is a local workspace for security findings. It lets you review findings reported by Hermes or other agents, inspect evidence and export reports across web, smart contract and other assets.

What Recat does

Recat reads a folder of security findings and presents them in a local web app. Each finding sits in project-name/bug/finding-name/ with a finding.json, a README.md and an optional poc/ folder. Fields include asset_type (web, smart_contract or other), status (candidate, confirmed or false_positive) and severity (critical, high, medium, low or info). The dashboard shows severity, status, activity and asset coverage, with search and filters by project, category, vulnerability class and status, plus an evidence viewer, JSON exports and project ZIP downloads.

Recat rescans the project folders every five seconds, displays reported results and preserves the original records. A reporting skill, recat-findings, lets an agent write findings straight into the source folder. The README lists install paths for Codex, Claude Code and Hermes, where the personal Hermes path is ~/.hermes/skills/recat-findings/SKILL.md and the skill is invoked with /recat-findings. Access can be protected with a password, and a censored view is available.

Key features

  • Dashboard of severity, status, activity and asset coverage
  • Search and filters by project, category, vulnerability class and status
  • Evidence viewer, JSON exports and project ZIP downloads
  • Findings read from a folder and rescanned every five seconds
  • Password access and a censored view
  • recat-findings skill for Codex, Claude Code and Hermes

When to use it

  • Triaging findings that a Hermes agent reports across web and smart contract targets
  • Marking findings as candidate, confirmed or false positive
  • Exporting evidence and project archives for a report

Who it is for: Security researchers who use AI agents to find vulnerabilities and want one local place to review and export the results.

How it fits with Hermes Agent

Hermes is one of three agents the reporting skill supports, alongside Codex and Claude Code, and the skill installs into ~/.hermes/skills.

How to install Recat

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

bun install
bun run dev

Requirements: Bun, a RECAT_PASSWORD set in .env, and a running server with access to the findings folder

FAQ

What is Recat?

Recat is a local web workspace for security findings. It shows findings written by agents, lets you inspect evidence and exports reports.

Does Recat work with Hermes Agent?

Yes. Its recat-findings skill can be installed at ~/.hermes/skills/recat-findings/SKILL.md and invoked with /recat-findings, and the agent writes findings into the source folder.

How do I install Recat?

Create .env from .env.example with a RECAT_PASSWORD, then run bun install and bun run dev. For production, run bun run build and bun run start, which binds to 127.0.0.1:5173 unless PORT is set.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely