KunLun-M
LoRexxar/Kunlun-M
Open-source static code security scanner with a built-in skill for AI agents including Hermes
KunLun-M is an open-source static code security analysis system that builds an AST graph and runs taint analysis to find vulnerabilities. It includes a built-in AI agent skill with one-click integration for Codex, Claude Code and Hermes.
What KunLun-M does
KunLun-M is a static code security analysis system. It builds an AST graph of the source, including the call graph, data flow and syntax structure, then runs taint analysis to detect vulnerabilities. The README lists 14 languages: PHP, JavaScript, TypeScript, Python, Java, Go, Ruby, Rust, C, C++, C#, Kotlin, Lua and Solidity. It runs in CLI, console and web modes.
Scan results can be exported as CSV, JSON, Markdown, HTML or XML. The web dashboard covers task management, project overview, scan results and an interactive graph view, and the console includes a Joern-style graph traversal REPL. Projects can also be exported to Neo4j. A built-in AI agent skill offers one-click integration with Codex, Claude Code and Hermes. The Quick Start installs from a git clone with pip and initializes a local database.
Key features
- AST graph engine with call graph, data flow and taint tracking
- 14 supported languages, from PHP and Python to Rust and Solidity
- CLI, interactive console and web dashboard modes
- Report export to CSV, JSON, Markdown, HTML or XML
- Graph traversal REPL and Neo4j export
- Built-in AI agent skill with one-click integration for Codex, Claude Code and Hermes
When to use it
- Scan a PHP, Python or JavaScript project for taint-based vulnerabilities
- Produce an HTML report of findings for a code review
- Explore call graphs and data flows interactively in the console
Who it is for: Security engineers and developers who audit source code for vulnerabilities and want a scanner that AI agents can be pointed at.
How it fits with Hermes Agent
The README names Hermes among the agents, with Codex and Claude Code, that the built-in AI agent skill integrates with in one click; the scanner itself is a general security tool.
How to install KunLun-M
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
git clone https://github.com/LoRexxar/Kunlun-M.git && cd Kunlun-M
pip install -r requirements.txt
cp Kunlun_M/settings.py.bak Kunlun_M/settings.py
python kunlun.py init FAQ
What is KunLun-M?
KunLun-M is an open-source static code security analysis system. It builds an AST graph from source code and runs taint analysis to detect vulnerabilities in 14 languages.
Does KunLun-M work with Hermes Agent?
The README says its built-in AI agent skill offers one-click integration with Codex, Claude Code and Hermes. The part of the README reviewed does not spell out the Hermes steps, so check the repository for details.
How do I install KunLun-M?
Clone the repository, run pip install -r requirements.txt, copy Kunlun_M/settings.py.bak to Kunlun_M/settings.py and run python kunlun.py init. Then scan with python kunlun.py scan -t /path/to/project.
Similar security for Hermes Agent
All securityHook that blocks dangerous git and shell commands before AI coding agents run them
lennney Stop That ShitHook and skill guard that stops AI coding agents from unrequested checksums and scope creep
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
SafeAI-Lab-X ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
Related guides: How to run Hermes Agent securely